CVE-2019-0708: BlueKeep
A remote code execution vulnerability in Windows Remote Desktop Services, triggered by a use-after-free condition in how the service handles a client disconnecting mid-session. It is wormable: malware could exploit it with no user interaction and spread automatically between vulnerable machines, similar to WannaCry.
View the authoritative record on NVD ↗Affected software
- Windows XP
- Windows Server 2003
- Windows Vista
- Windows 7
- Windows Server 2008
- Windows Server 2008 R2
How it's exploited
Connect to an exposed RDP service and send a sequence of crafted virtual channel requests that trigger a use-after-free during disconnect handling, giving an unauthenticated attacker code execution.
Severity
CVE-2019-0708 carries a CVSS 3.0 base score of 9.8, rated Critical. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2019-0708 is categorized under CWE-416, the general weakness pattern behind this specific vulnerability.
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Remediation
Apply Microsoft's May 2019 security update (issued even for out-of-support Windows XP and Server 2003), and never expose RDP (port 3389) directly to the internet, use a VPN or Remote Desktop Gateway instead.
Frequently asked questions
What is CVE-2019-0708?
A remote code execution vulnerability in Windows Remote Desktop Services, triggered by a use-after-free condition in how the service handles a client disconnecting mid-session. It is wormable: malware could exploit it with no user interaction and spread automatically between vulnerable machines, similar to WannaCry.
How severe is CVE-2019-0708?
CVE-2019-0708 has a CVSS 3.0 base score of 9.8 out of 10, rated Critical.
What software is affected by CVE-2019-0708?
CVE-2019-0708 affects Windows XP; Windows Server 2003; Windows Vista; Windows 7; Windows Server 2008; Windows Server 2008 R2.
How do you fix CVE-2019-0708?
Apply Microsoft's May 2019 security update (issued even for out-of-support Windows XP and Server 2003), and never expose RDP (port 3389) directly to the internet, use a VPN or Remote Desktop Gateway instead.
Where is the authoritative record for CVE-2019-0708?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2019-0708 at https://nvd.nist.gov/vuln/detail/CVE-2019-0708, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest