---
cve: "CVE-2019-0708"
severity: "CRITICAL"
cvss: 9.8
epss: "100%"
vendor: "Microsoft"
kev: true
exploited: true
published: "2019-05-16 19:29:00"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T09:37:50+02:00"
---

# CVE-2019-0708

> 9.8 CRITICAL · ⚠️ CISA KEV (1770 Tage) · 🔓 Exploited · 🧪 PoC

## Beschreibung

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Exploit-Evidenz

- [EDB-47416 — Microsoft Windows - BlueKeep RDP Remote Windows Kernel Use After Free (Metasploit)](https://www.exploit-db.com/exploits/47416) ✅
- [EDB-47683 — Microsoft Windows 7 (x86) - 'BlueKeep' Remote Desktop Protocol (RDP) Remote Windows Kernel Use After Free](https://www.exploit-db.com/exploits/47683)
- [EDB-47120 — Microsoft Windows Remote Desktop - 'BlueKeep' Denial of Service (Metasploit)](https://www.exploit-db.com/exploits/47120)
- [EDB-46946 — Microsoft Windows Remote Desktop - 'BlueKeep' Denial of Service](https://www.exploit-db.com/exploits/46946)

## Referenzen

- <https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708>
- <https://cert-portal.siemens.com/productcert/pdf/ssa-932041.pdf>
- <https://cert-portal.siemens.com/productcert/pdf/ssa-616199.pdf>
- <https://cert-portal.siemens.com/productcert/pdf/ssa-433987.pdf>
- <https://cert-portal.siemens.com/productcert/pdf/ssa-832947.pdf>
- <https://cert-portal.siemens.com/productcert/pdf/ssa-166360.pdf>
- <https://cert-portal.siemens.com/productcert/pdf/ssa-406175.pdf>
- <http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190529-01-windows-en>
- <http://www.huawei.com/en/psirt/security-notices/huawei-sn-20190515-01-windows-en>
- <http://packetstormsecurity.com/files/153133/Microsoft-Windows-Remote-Desktop-BlueKeep-Denial-Of-Service.html>
- <http://packetstormsecurity.com/files/153627/Microsoft-Windows-RDP-BlueKeep-Denial-Of-Service.html>
- <http://packetstormsecurity.com/files/154579/BlueKeep-RDP-Remote-Windows-Kernel-Use-After-Free.html>
- <http://packetstormsecurity.com/files/155389/Microsoft-Windows-7-x86-BlueKeep-RDP-Use-After-Free.html>
- <http://packetstormsecurity.com/files/162960/Microsoft-RDP-Remote-Code-Execution.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2019-0708) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
