← Vulnerability feed

Vulnerability record · CVE-2019-0708 · published 16 May 2019

CVE-2019-0708: Microsoft Remote Desktop Services use-after-free remote code execution

Microsoft · Windows 7

Remote Desktop Services (formerly Terminal Services) contains a use-after-free flaw that lets an unauthenticated attacker execute code by sending specially crafted requests over RDP. It is wormable in nature and affects legacy Windows 7 and Windows Server 2008 systems as well as several third-party products that embed the affected stack.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 100% · top 0.1% CWE-416 · Use after free
9.8CVSS 3.1 base score, v2 10.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
67Affected product versions listed by NVD
29References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated, wormable remote code execution with a 9.8 CVSS score, KEV listing, known ransomware use and near-certain EPSS probability.

What it is

Remote Desktop Services (formerly Terminal Services) contains a use-after-free flaw that lets an unauthenticated attacker execute code by sending specially crafted requests over RDP. It is wormable in nature and affects legacy Windows 7 and Windows Server 2008 systems as well as several third-party products that embed the affected stack.

Impact

An attacker gains remote code execution at the level of the RDP service, typically SYSTEM, allowing full compromise of the host without any credentials.

Attack surface

Reachable over the network via RDP (TCP 3389) with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or network-exposed RDP endpoint on an unpatched system is a candidate.

Exploitation

Listed in CISA KEV since 2021-11-03 with known ransomware campaign use, and EPSS probability is effectively 1.0 (99.999th percentile). Multiple public exploit references exist, including working RCE and DoS proof-of-concepts.

What to do

  • Apply the Microsoft security update for CVE-2019-0708 on all affected Windows 7 and Windows Server 2008 systems, and apply vendor firmware updates for the listed Siemens, Huawei and other affected products.
  • Enable Network Level Authentication (NLA) on RDP endpoints to block unauthenticated pre-auth exploitation.
  • Block or restrict TCP 3389 at the perimeter and between network segments; do not expose RDP directly to the internet.
  • Disable Remote Desktop Services where it is not required, and retire or isolate unsupported end-of-life systems that cannot be patched.
  • Monitor for and block exploitation attempts using vendor and third-party detection guidance for BlueKeep.

Detection

  • Audit for RDP (TCP 3389) exposed to untrusted networks and for unpatched Windows 7 / Server 2008 hosts still running Remote Desktop Services.
  • Monitor RDP connection logs and network traffic for anomalous pre-authentication request patterns or crashes of the RDP service (TermService) consistent with use-after-free exploitation.
  • Alert on unexpected service crashes, SYSTEM-level process creation, or new listening services on hosts that expose RDP.
  • Correlate EDR/AV telemetry for known BlueKeep exploit signatures and for post-exploitation activity on RDP-exposed systems.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-0708 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Remote Desktop Services Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

67 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/153133/Microsoft-Windows-Remote-Desktop-BlueKeep-Denial-Of-Service.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/153627/Microsoft-Windows-RDP-BlueKeep-Denial-Of-Service.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/154579/BlueKeep-RDP-Remote-Windows-Kernel-Use-After-Free.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/155389/Microsoft-Windows-7-x86-BlueKeep-RDP-Use-After-Free.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/162960/Microsoft-RDP-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190529-01-windows-en Third Party Advisory
http://www.huawei.com/en/psirt/security-notices/huawei-sn-20190515-01-windows-en Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-166360.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-406175.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-433987.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-616199.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-832947.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-932041.pdf Third Party Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708 PatchVendor Advisory
http://packetstormsecurity.com/files/153133/Microsoft-Windows-Remote-Desktop-BlueKeep-Denial-Of-Service.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/153627/Microsoft-Windows-RDP-BlueKeep-Denial-Of-Service.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/154579/BlueKeep-RDP-Remote-Windows-Kernel-Use-After-Free.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/155389/Microsoft-Windows-7-x86-BlueKeep-RDP-Use-After-Free.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/162960/Microsoft-RDP-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190529-01-windows-en Third Party Advisory
http://www.huawei.com/en/psirt/security-notices/huawei-sn-20190515-01-windows-en Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-166360.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-406175.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-433987.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-616199.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-832947.pdf Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-932041.pdf Third Party Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708 PatchVendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0708 US Government Resource

Track CVE-2019-0708 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.0CVE-2026-68820Windows Ancillary Function Driver for WinSock use-after-free privilege escalationThe Windows Ancillary Function Driver for WinSock (afd.sys) contains a use-after-free (CWE-416) that lets an authorized local attacker elevate privil…KEVEPSS 0.33%analysed8.8CVE-2010-0806Microsoft Internet Explorer Peer Objects use-after-free allows remote code executionInternet Explorer 6, 6 SP1 and 7 contain a use-after-free in the Peer Objects component (iepeers.dll), where an object is accessed after deletion, le…KEVEPSS 82%analysed8.8CVE-2010-0249Microsoft Internet Explorer use-after-free enables remote code executionInternet Explorer 6, 7 and 8 mishandle objects in memory, leaving a dangling pointer that can be reused after the object is freed. A remote attacker …KEVEPSS 92%analysed7.8CVE-2020-9715Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat and Reader contain a use-after-free (CWE-416) flaw affecting versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and ea…KEVEPSS 49%analysed8.8CVE-2026-5281Google Chrome Dawn use-after-free allows remote code executionChrome versions before 146.0.7680.178 contain a use-after-free flaw in the Dawn graphics component. An attacker who has already compromised the rende…KEVEPSS 0.70%analysed8.8CVE-2023-43000Apple WebKit use-after-free via malicious web contentA use-after-free flaw in Apple's WebKit engine was fixed by improved memory management in macOS Ventura 13.5, iOS/iPadOS 16.6, Safari 16.6, and iOS/i…KEVEPSS 3.9%analysed7.8CVE-2023-41974Apple iOS and iPadOS use-after-free allows kernel code executionA use-after-free flaw in Apple iOS and iPadOS was fixed through improved memory management in iOS 17, iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. Becaus…KEVEPSS 1.4%analysed8.8CVE-2026-2441Google Chrome CSS use-after-free enables sandbox code executionChrome before 145.0.7632.75 contains a use-after-free in CSS handling. A crafted HTML page can trigger the flaw and let a remote attacker run arbitra…KEVEPSS 55%analysed

Source: NIST National Vulnerability Database (record CVE-2019-0708), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.