← Vulnerability feed

Vulnerability record · CVE-2019-0887 · published 15 July 2019

CVE-2019-0887: Microsoft Remote Desktop Services clipboard redirection path traversal RCE

Microsoft · Remote Desktop Client

CVE-2019-0887 is a path traversal (CWE-22) flaw in Microsoft Remote Desktop Services that an authenticated attacker can abuse through clipboard redirection to achieve remote code execution. It matters because RDP clipboard sharing is widely enabled by default, and the flaw affects both the RDP client and a broad set of Windows client and server versions.

8.0 CVSS 3.1 High EPSS 71% · top 0.6% CWE-22 · Path traversal
8.0CVSS 3.1 base score, v2 8.5
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
10Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 8.0 with a very high EPSS percentile and public exploit research, though it requires authentication and user interaction and is not in KEV.

What it is

CVE-2019-0887 is a path traversal (CWE-22) flaw in Microsoft Remote Desktop Services that an authenticated attacker can abuse through clipboard redirection to achieve remote code execution. It matters because RDP clipboard sharing is widely enabled by default, and the flaw affects both the RDP client and a broad set of Windows client and server versions.

Impact

An authenticated attacker can write files outside the intended clipboard redirection directory and execute code on the target system, gaining the privileges of the affected process.

Attack surface

Reached over the network via an RDP session with clipboard redirection enabled; the attacker must be authenticated (PR:L) and some form of user interaction is required (UI:R) per the CVSS vector.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.70966, 99.37th percentile) and public technical descriptions exist from Check Point research, indicating meaningful exploitation interest.

What to do

  • Apply the Microsoft security update referenced in the vendor advisory for CVE-2019-0887.
  • Disable or restrict RDP clipboard redirection where it is not operationally required.
  • Limit RDP exposure to trusted networks and require strong authentication for remote sessions.
  • Monitor and restrict which accounts can initiate RDP sessions to reduce the authenticated attack surface.

Detection

  • Alert on unexpected file creation or modification outside expected clipboard or temp directories during active RDP sessions.
  • Monitor RDP session logs for clipboard redirection events correlated with suspicious process execution.
  • Hunt for path traversal patterns in clipboard-related file paths on RDP hosts and clients.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-0887 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-0708Microsoft Remote Desktop Services use-after-free remote code executionRemote Desktop Services (formerly Terminal Services) contains a use-after-free flaw that lets an unauthenticated attacker execute code by sending spe…KEVEPSS 100%analysed9.8CVE-2017-8543Windows Search memory handling flaw allows remote code executionWindows Search fails to properly handle objects in memory, allowing an unauthenticated remote attacker to execute code on affected Windows systems. T…KEVEPSS 74%analysed9.8CVE-2015-1635Microsoft HTTP.sys remote code execution via crafted HTTP requestsHTTP.sys in multiple Windows versions fails to properly handle crafted HTTP requests, allowing remote code execution. The flaw is reachable over the …KEVEPSS 100%analysed8.8CVE-2024-43461Windows MSHTML Platform spoofing flaw enables code executionCVE-2024-43461 is a spoofing vulnerability in the Windows MSHTML platform, the legacy rendering engine still reachable through Windows components. Th…KEVEPSS 54%analysed8.8CVE-2024-30040Windows MSHTML platform security feature bypass via improper input validationCVE-2024-30040 is a security feature bypass in the Windows MSHTML platform caused by improper input validation. Because MSHTML is the legacy renderin…KEVEPSS 3.9%analysed8.8CVE-2024-29988Microsoft Windows SmartScreen Prompt Security Feature BypassCVE-2024-29988 is a security feature bypass in the Microsoft Windows SmartScreen prompt. An attacker can craft a file or content that evades the Smar…KEVEPSS 45%analysed8.8CVE-2023-36025Windows SmartScreen security feature bypassCVE-2023-36025 is a security feature bypass in Microsoft Windows SmartScreen, the component that warns users before running files downloaded from the…KEVEPSS 88%analysed8.8CVE-2023-32049Windows SmartScreen security feature bypassCVE-2023-32049 is a security feature bypass in Microsoft Windows SmartScreen, the component that warns users about untrusted files and downloads. A s…KEVEPSS 4.2%analysed

Source: NIST National Vulnerability Database (record CVE-2019-0887), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.