CVE-2019-0708

ENISA EUVD: EUVD-2019-1468 ↗
Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 11 articles Published: 2019-05-16

EPSS Score

Source: FIRST.org · 2026-05-23
94.45%
probability
This CVE has a 94.45% probability of being exploited in the next 30 days.
0% Top 100.0th percentile of all CVEs 100%

CVSS v3.1

Source: VulnerabilityLookup (CIRCL)
9.8
CRITICAL
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2 (legacy)

10.0
HIGH
Access Vector
Network
Access Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
AV:N/AC:L/Au:N/C:C/I:C/A:C

Description

VulnerabilityLookup (CNA)
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

Affected Products

Microsoft
Windows
7 for 32-bit Systems Service Pack 1 7 for x64-based Systems Service Pack 1
Microsoft
Windows Server
2008 R2 for x64-based Systems Service Pack 1 (Core installation) 2008 R2 for Itanium-Based Systems Service Pack 1 2008 R2 for x64-based Systems Service Pack 1 2008 for 32-bit Systems Service Pack 2 (Core installation) 2008 for Itanium-Based Systems Service Pack 2 2008 for 32-bit Systems Service Pack 2

Attack Intelligence

Exploits & PoC

Ekultek/BlueKeep

Proof of concept for CVE-2019-0708

1183 2026-03-16
robertdavidgraham/rdpscan

A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability.

917 2019-06-22
496 2019-06-01
k8gege/CVE-2019-0708

3389远程桌面代码执行漏洞CVE-2019-0708批量检测工具(Rdpscan Bluekeep Check)

391 2019-06-13
algo7/bluekeep_CVE-2019-0708_poc_to_exploit

An Attempt to Port BlueKeep PoC from @Ekultek to actual exploits

344 2021-01-10
cbwang505/CVE-2019-0708-EXP-Windows

CVE-2019-0708-EXP-Windows版单文件exe版,运行后直接在当前控制台反弹System权限Shell

318 2020-01-21
0xeb-bp/bluekeep

Public work for CVE-2019-0708

293 2019-11-19
Cyb0r9/ispy

ispy V1.0 - Eternalblue(ms17-010)/Bluekeep(CVE-2019-0708) Scanner and exploit ( Metasploit automation )

242 2021-02-06
RICSecLab/CVE-2019-0708

CVE-2019-0708 (BlueKeep) proof of concept allowing pre-auth RCE on Windows7

149 2022-03-28
Leoid/CVE-2019-0708

Only Hitting PoC [Tested on Windows Server 2008 r2]

127 2019-05-28
p0p0p0/CVE-2019-0708-exploit

CVE-2019-0708-exploit

120 2019-05-15
worawit/CVE-2019-0708

CVE-2019-0708 (BlueKeep)

110 2020-07-07
biggerwing/CVE-2019-0708-poc

CVE-2019-0708 远程代码执行漏洞批量检测

82 2019-05-30
coolboy4me/cve-2019-0708_bluekeep_rce

it works on xp (all version sp2 sp3)

75 2019-09-30
hook-s3c/CVE-2019-0708-poc

proof of concept exploit for Microsoft Windows 7 and Server 2008 RDP vulnerability

47 2019-05-15
umarfarook882/CVE-2019-0708

CVE-2019-0708 - BlueKeep (RDP)

40 2020-06-14
syriusbughunt/CVE-2019-0708

PoC about CVE-2019-0708 (RDP; Windows 7, Windows Server 2003, Windows Server 2008)

39 2019-05-16
rockmelodies/CVE-2019-0708-Exploit

Using CVE-2019-0708 to Locally Promote Privileges in Windows 10 System

31 2019-05-15
HynekPetrak/detect_bluekeep.py

Python script to detect bluekeep vulnerability (CVE-2019-0708) with TLS/SSL and x509 support

27 2019-06-12
mekhalleh/cve-2019-0708

Metasploit module for massive Denial of Service using #Bluekeep vector.

25 2019-10-01
19 2019-06-01
19 2019-05-29
fourtwizzy/CVE-2019-0708-Check-Device-Patch-Status

Powershell script to run and determine if a specific device has been patched for CVE-2019-0708. This checks to see if the termdd.sys file has been up

18 2019-08-28
cve-2019-0708-poc/cve-2019-0708

CVE-2019-0708 Exploit Tool

18 2019-07-18
gobysec/CVE-2019-0708

Goby support CVE-2019-0708 "BlueKeep" vulnerability check

17 2019-05-23
cvencoder/cve-2019-0708

POC CVE-2019-0708 with python script!

14 2019-06-24
SherlockSec/CVE-2019-0708

A Win7 RDP exploit

13 2019-05-14
closethe/CVE-2019-0708-POC

cve-2019-0708 poc .

13 2019-05-24
Pa55w0rd/CVE-2019-0708

CVE-2019-0708批量检测

13 2021-03-31
RickGeex/msf-module-CVE-2019-0708

Metasploit module for CVE-2019-0708 (BlueKeep) - https://github.com/rapid7/metasploit-framework/tree/5a0119b04309c8e61b44763ac08811cd3ecbbf8d/modules/

13 2019-09-07
skyshell20082008/CVE-2019-0708-PoC-Hitting-Path

It's only hitting vulnerable path in termdd.sys!!! NOT DOS

12 2019-05-19
wqsemc/CVE-2019-0708

initial exploit for CVE-2019-0708, BlueKeep CVE-2019-0708 BlueKeep RDP Remote Windows Kernel Use After Free The RDP termdd.sys driver improperly hand

12 2019-09-16
n0auth/CVE-2019-0708

Totally legitimate

11 2019-05-15
qing-root/CVE-2019-0708-EXP-MSF-

CVE-2019-0708-EXP(MSF) Vulnerability exploit program for cve-2019-0708

11 2019-09-07
anquanscan/CVE-2019-0708

CVE-2019-0708 exp

9 2019-05-15
7 2019-08-28
SugiB3o/Check-vuln-CVE-2019-0708

Check vuln CVE 2019-0708

7 2019-05-23
NullByteSuiteDevs/CVE-2019-0708

PoC exploit for BlueKeep (CVE-2019-0708)

6 2019-05-15
blockchainguard/CVE-2019-0708

CVE-2019-0708漏洞MSF批量巡检插件

5 2019-05-23
ht0Ruial/CVE-2019-0708Poc-BatchScanning

基于360公开的无损检测工具的可直接在windows上运行的批量检测程序

5 2019-05-28
eastmountyxz/CVE-2019-0708-Windows

这篇文章将分享Windows远程桌面服务漏洞(CVE-2019-0708),并详细讲解该漏洞及防御措施。作者作为网络安全的小白,分享一些自学基础教程给大家,主要是关于安全工具和实践操作的在线笔记,希望您们喜欢。同时,更希望您能与我一起操作和进步,后续将深入学习网络安全和系统安全知识并分享相关实验。总

5 2020-03-13
pry0cc/BlueKeepTracker

My bot (badly written) to search and monitor cve-2019-0708 repositories

4 2019-05-21
turingcompl33t/bluekeep

Research Regarding CVE-2019-0708.

4 2019-11-04
FrostsaberX/CVE-2019-0708

CVE-2019-0708 With Metasploit-Framework Exploit

4 2019-09-07
Ravaan21/Bluekeep-Hunter

CVE-2019-0708, A tool which mass hunts for bluekeep vulnerability for exploitation.

4 2023-03-12
areusecure/CVE-2019-0708

Proof of concept exploit for CVE-2019-0708

3 2019-05-15
pry0cc/cve-2019-0708-2

Testing my new bot out

3 2019-05-15
victor0013/CVE-2019-0708

Scanner PoC for CVE-2019-0708 RDP RCE vuln

3 2019-05-22
3 2019-05-27
andripwn/CVE-2019-0708

Scanner PoC for CVE-2019-0708 RDP RCE vuln

3 2020-09-20
ShadowBrokers-ExploitLeak/CVE-2019-0708

A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker conne

2 2019-05-16
ttsite/CVE-2019-0708-

Announces fraud

2 2019-06-11
edvacco/CVE-2019-0708-POC

根据360的程序,整的CVE-2019-0708批量检测

2 2019-05-21
smallFunction/CVE-2019-0708-POC

Working proof of concept for CVE-2019-0708, spawns remote shell.

2 2019-05-23
skommando/CVE-2019-0708

CVE-2019-0708 BlueKeep漏洞批量扫描工具和POC,暂时只有蓝屏。

2 2019-09-12
1 2019-05-15
sbkcbig/CVE-2019-0708-EXPloit

POCexp:https://pan.baidu.com/s/184gN1tJVIOYqOjaezM_VsA 提取码:e2k8

1 2019-05-15
YSheldon/MS_T120

CVE-2019-0708

1 2019-05-15
hotdog777714/RDS_CVE-2019-0708

exploit CVE-2019-0708 RDS

1 2019-05-15
sbkcbig/CVE-2019-0708-Poc-exploit

CVE-2019-0708 EXPloit-poc 漏洞描述 微软官方紧急发布安全补丁,修复了一个Windows远程桌面服务的远程代码执行漏洞CVE-2019-0708,该漏洞影响了某些旧版本的Windows系统。此漏洞是预身份验证,无需用户交互。当未经身份验证的攻击者使用RDP(常见端口3389

1 2019-05-15
Barry-McCockiner/CVE-2019-0708

A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker conne

1 2019-05-16
safly/CVE-2019-0708

CVE-2019-0708 demo

1 2019-05-16
303sec/CVE-2019-0708

POC for CVE-2019-0708

1 2019-05-17
1 2019-05-17
1 2019-07-04
freeide/CVE-2019-0708

High level exploit

1 2019-05-15
herhe/CVE-2019-0708poc

根据360Vulcan Team开发的CVE-2019-0708单个IP检测工具构造了个批量检测脚本而已

1 2019-05-27
1 2019-05-30
Gh0st0ne/rdpscan-BlueKeep

A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability.

1 2019-05-30
AdministratorGithub/CVE-2019-0708

CVE-2019-0708批量蓝屏恶搞

1 2019-07-09
cream-sec/CVE-2019-0708-Msf--

CVE-2019-0708-Msf-验证

1 2019-06-12
ntkernel0/CVE-2019-0708

收集网上CVE-2018-0708的poc和exp(目前没有找到exp)

1 2019-07-25
0x6b7966/CVE-2019-0708-RCE

CVE-2019-0708 RCE远程代码执行getshell教程

1 2019-09-07
0xFlag/CVE-2019-0708-test

CVE-2019-0708 C#验证漏洞

1 2019-09-13
JSec1337/Scanner-CVE-2019-0708

Scanner CVE-2019-0708

1 2020-03-17
nochemax/bLuEkEeP-GUI

vulnerabilidad CVE-2019-0708 testing y explotacion

1 2020-05-23
CircuitSoul/CVE-2019-0708

POC-CVE-2019-0708

1 2021-06-19
tranqtruong/Detect-BlueKeep

a simple tool to detect the exploitation of BlueKeep vulnerability (CVE-2019-0708)

1 2025-06-04
0 2019-05-15
xiyangzuishuai/Dark-Network-CVE-2019-0708

Dark Net Sunset New Release CVE-2019-0708

0 2019-05-15
sbkcbig/CVE-2019-0708-EXPloit-3389

EXPloit-poc: https://pan.baidu.com/s/184gN1tJVIOYqOjaezM_VsA 提取码:e2k8

0 2019-05-15
f8al/CVE-2019-0708-POC

PoC for CVE-2019-0708

0 2019-05-28
freeide/CVE-2019-0708-PoC-Exploit

CVE-2019-0708 PoC Exploit

0 2019-05-23
SQLDebugger/CVE-2019-0708-Tool

50 first stargazers will get get the tool via email

0 2019-05-31
oneoy/BlueKeep

CVE-2019-0708 bluekeep 漏洞检测

0 2019-05-29
0 2019-06-11
0 2019-05-31
ZhaoYukai/CVE-2019-0708-Batch-Blue-Screen

改写某大佬写的0708蓝屏脚本 改为网段批量蓝屏

0 2019-06-06
Micr067/CVE-2019-0708RDP-MSF

CVE-2019-0708RDP MSF

0 2019-09-07
Ameg-yag/Wincrash

Mass exploit for CVE-2019-0708

0 2019-10-11
ryan-ally/rdp0708scanner

cve-2019-0708 vulnerablility scanner

0 2019-05-22
sezayi1972/CVE-2019-0708

CVE-2019-0708 Exploit

0 2019-05-18
0 2022-04-20
davidfortytwo/bluekeep

Checker and exploit for Bluekeep CVE-2019-0708 vulnerability

0 2023-06-01
gousseine-systems/vuln-rabilit-windows7

ecrit un script python de correction de la vulnérabilités windows 7 pour réponse automatique de wazuh: CVE-2017-0143 (MS17-010 - EternalBlue) CVE-2019

0 2024-03-28
denuwanjayasekara/CVE-Exploitation-Reports

CVE Exploitation Reports: CVE-2007-3280, CVE-2017-0144, CVE-2019-0708

0 2024-09-11
GopeshKachhadiya/Windows-2

A hands-on Windows 7 lab designed to demonstrate the real-world impact of the BlueKeep (CVE-2019-0708) vulnerability through practical exploitation an

0 2026-01-09
emmadej1234/bluekeep-metasploit-lab-project

Exploiting BlueKeep (CVE-2019-0708) on Windows 7 using Metasploit

0 2026-04-17
Ayomide-29/bluekeep_metasploit_practice

Exploiting bluekeep (CVE-2019-0708) on windows 7 using metasplotable

0 2026-04-17
ayomideadams61-hub/bluekeep-metsploitable-lab

Exploiting bluekeep (CVE-2019-0708)on windows 7 using metasploit (Educational lab)

0 2026-04-17
Nweks/Bluekeep-Metasploit-Lab-Project

Exploiting Bluekeep (CVE-2019-0708) on windows 7 using metasploit (Esucational lab)

0 2026-04-19
126 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
92%
EPSS 94.45%
CVSS v3.1 9.8
Mentions 11
Last Seen May 08, 2025

CNA Information

CNA Assigner
microsoft

Analyst Note

CVE-2019-0708 (BlueKeep) is a confirmed zero-day. It was exploited in the wild before patches were available, with exploitation documented in May 2019 shortly after disclosure. This critical RDP vulnerability achieved widespread recognition as a zero-day due to active exploitation of unpatched systems and the rapid emergence of exploit code in the threat landscape.

Threat Actors 23

MuddyWater
apt_group Information theft and espionage 🇮🇷 IR
Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
Turla Group
apt_group Information theft and espionage Russian Federation
APT 29
apt_group Information theft and espionage 🇷🇺 RU
APT 28
apt_group Information theft and espionage 🇷🇺 RU
Cron
apt_group 🇷🇺 RU
Kimsuky
apt_group Information theft and espionage 🇰🇷 KR
Harvester
apt_group Information theft and espionage Unknown
Hacking Team
apt_group 🇮🇹 IT
Kinsing
apt_group 🇷🇺 RU
Gamaredon Group
apt_group Information theft and espionage 🇷🇺 RU
Equation Group
apt_group Sabotage and destruction 🇺🇸 US
Infy
apt_group Information theft and espionage 🇮🇷 IR
TeamTNT
apt_group 🇩🇪 DE
GhostR
apt_group 🇨🇳 CN
Pirate Panda
apt_group Information theft and espionage 🇨🇳 CN
TAG-100
apt_group Information theft and espionage 🇨🇳 CN
TAG-28
apt_group Information theft and espionage 🇨🇳 CN
UNC5174
apt_group 🇨🇳 CN
Hurricane Panda
apt_group Information theft and espionage 🇨🇳 CN
Red October
apt_group 🇷🇺 RU
Scarred Manticore
apt_group Information theft and espionage 🇮🇷 IR
LightBasin
apt_group Information theft and espionage 🇨🇳 CN

Triage Info

Decided atMar 05, 2026
Published DateMay 16, 2019