November 3, 2021 · Applied Cybernetics Group
CVE-2019-0708 — Microsoft Remote Desktop Services
known ransomware use
Microsoft Remote Desktop Services Remote Code Execution Vulnerability
- Added to KEV
2021-11-03- Federal due date
2022-05-03- Vendor
- Microsoft
- Product
- Remote Desktop Services
- EPSS
- 100.0th percentile (score 0.945, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2019-0708
CISA short description
Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.
Required action
Apply updates per vendor instructions.