CVE-2019-0708
ENISA EUVD: EUVD-2019-1468 ↗
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
11 articles
EPSS Score
Source: FIRST.org · 2026-05-24
94.45%
probability
This CVE has a 94.45% probability
of being exploited in the next 30 days.
0%
Top 100.0th percentile of all CVEs
100%
CVSS v3.1
Source: NVD9.8
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
Attack Intelligence
CWE-118
· Incorrect Access of Indexable Resource ('Range Error')
CWE-119
· Buffer Overflow
CWE-416
· Use After Free
CWE-664
· Improper Control of a Resource Through its Lifetime
CWE-666
· Operation on Resource in Wrong Phase of Lifetime
CWE-672
· Operation on a Resource after Expiration or Release
CWE-825
· Expired Pointer Dereference
Exploits & PoC
Ekultek/BlueKeep
Proof of concept for CVE-2019-0708
1186
496
k8gege/CVE-2019-0708
3389远程桌面代码执行漏洞CVE-2019-0708批量检测工具(Rdpscan Bluekeep Check)
390
algo7/bluekeep_CVE-2019-0708_poc_to_exploit
An Attempt to Port BlueKeep PoC from @Ekultek to actual exploits
344
0xeb-bp/bluekeep
Public work for CVE-2019-0708
296
Cyb0r9/ispy
ispy V1.0 - Eternalblue(ms17-010)/Bluekeep(CVE-2019-0708) Scanner and exploit ( Metasploit automation )
242
RICSecLab/CVE-2019-0708
CVE-2019-0708 (BlueKeep) proof of concept allowing pre-auth RCE on Windows7
149
Leoid/CVE-2019-0708
Only Hitting PoC [Tested on Windows Server 2008 r2]
127
8 repos — triés par ⭐
Rechercher sur GitHub ↗
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
Qualys
May 08, 2025
BlueKeep Attacks Observed Months after Initial Release
Qualys
Nov 04, 2019
May 2019 Patch Tuesday – 79 Vulns, 22 Critical, RDP RCE, MDS Attacks, Adobe Vulns
Qualys
May 14, 2019
Unpacking the CVEs in the FireEye Breach – Start Here First
Qualys
Feb 01, 2021
Solorigate/Sunburst : Theft of Cybersecurity Tools | FireEye Breach
Qualys
Dec 10, 2020
10 Critical Network Pentest Findings IT Teams Overlook
TheHackerNews
Kimsuky Exploits BlueKeep RDP Vulnerability to Breach Systems in South Korea and Japan
TheHackerNews
Security Advisory 2019-013
CERT-EU
May 16, 2019
Signal Intelligence
Confidence
92%
EPSS
94.45%
CVSS v3.1
9.8
Mentions
11
Last Seen
May 08, 2025
CNA Information
Analyst Note
CVE-2019-0708 (BlueKeep) is a confirmed zero-day. It was exploited in the wild before patches were available, with exploitation documented in May 2019 shortly after disclosure. This critical RDP vulnerability achieved widespread recognition as a zero-day due to active exploitation of unpatched systems and the rapid emergence of exploit code in the threat landscape.
Threat Actors 23
MuddyWater
apt_group
Information theft and espionage
🇮🇷 IR
Lazarus Group
apt_group
Information theft and espionage
🇰🇵 KP
Turla Group
apt_group
Information theft and espionage
Russian Federation
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
Cron
apt_group
🇷🇺 RU
Kimsuky
apt_group
Information theft and espionage
🇰🇷 KR
Harvester
apt_group
Information theft and espionage
Unknown
Hacking Team
apt_group
🇮🇹 IT
Kinsing
apt_group
🇷🇺 RU
Gamaredon Group
apt_group
Information theft and espionage
🇷🇺 RU
Equation Group
apt_group
Sabotage and destruction
🇺🇸 US
Infy
apt_group
Information theft and espionage
🇮🇷 IR
TeamTNT
apt_group
🇩🇪 DE
GhostR
apt_group
🇨🇳 CN
Pirate Panda
apt_group
Information theft and espionage
🇨🇳 CN
TAG-100
apt_group
Information theft and espionage
🇨🇳 CN
TAG-28
apt_group
Information theft and espionage
🇨🇳 CN
UNC5174
apt_group
🇨🇳 CN
Hurricane Panda
apt_group
Information theft and espionage
🇨🇳 CN
Red October
apt_group
🇷🇺 RU
Scarred Manticore
apt_group
Information theft and espionage
🇮🇷 IR
LightBasin
apt_group
Information theft and espionage
🇨🇳 CN
Triage Info
Decided atMar 05, 2026