Vulnerability record · CVE-2019-0708 · published 16 May 2019
CVE-2019-0708: Microsoft Remote Desktop Services use-after-free remote code execution
Microsoft · Windows 7
Remote Desktop Services (formerly Terminal Services) contains a use-after-free flaw that lets an unauthenticated attacker execute code by sending specially crafted requests over RDP. It is wormable in nature and affects legacy Windows 7 and Windows Server 2008 systems as well as several third-party products that embed the affected stack.
Description
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated, wormable remote code execution with a 9.8 CVSS score, KEV listing, known ransomware use and near-certain EPSS probability.
What it is
Remote Desktop Services (formerly Terminal Services) contains a use-after-free flaw that lets an unauthenticated attacker execute code by sending specially crafted requests over RDP. It is wormable in nature and affects legacy Windows 7 and Windows Server 2008 systems as well as several third-party products that embed the affected stack.
Impact
An attacker gains remote code execution at the level of the RDP service, typically SYSTEM, allowing full compromise of the host without any credentials.
Attack surface
Reachable over the network via RDP (TCP 3389) with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or network-exposed RDP endpoint on an unpatched system is a candidate.
Exploitation
Listed in CISA KEV since 2021-11-03 with known ransomware campaign use, and EPSS probability is effectively 1.0 (99.999th percentile). Multiple public exploit references exist, including working RCE and DoS proof-of-concepts.
What to do
- Apply the Microsoft security update for CVE-2019-0708 on all affected Windows 7 and Windows Server 2008 systems, and apply vendor firmware updates for the listed Siemens, Huawei and other affected products.
- Enable Network Level Authentication (NLA) on RDP endpoints to block unauthenticated pre-auth exploitation.
- Block or restrict TCP 3389 at the perimeter and between network segments; do not expose RDP directly to the internet.
- Disable Remote Desktop Services where it is not required, and retire or isolate unsupported end-of-life systems that cannot be patched.
- Monitor for and block exploitation attempts using vendor and third-party detection guidance for BlueKeep.
Detection
- Audit for RDP (TCP 3389) exposed to untrusted networks and for unpatched Windows 7 / Server 2008 hosts still running Remote Desktop Services.
- Monitor RDP connection logs and network traffic for anomalous pre-authentication request patterns or crashes of the RDP service (TermService) consistent with use-after-free exploitation.
- Alert on unexpected service crashes, SYSTEM-level process creation, or new listening services on hosts that expose RDP.
- Correlate EDR/AV telemetry for known BlueKeep exploit signatures and for post-exploitation activity on RDP-exposed systems.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-0708 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Remote Desktop Services Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
67 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-0708 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-0708), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.