Vulnerability record · CVE-2019-0887 · published 15 July 2019
CVE-2019-0887: Microsoft Remote Desktop Services clipboard redirection path traversal RCE
Microsoft · Remote Desktop Client
CVE-2019-0887 is a path traversal (CWE-22) flaw in Microsoft Remote Desktop Services that an authenticated attacker can abuse through clipboard redirection to achieve remote code execution. It matters because RDP clipboard sharing is widely enabled by default, and the flaw affects both the RDP client and a broad set of Windows client and server versions.
Description
A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.0 with a very high EPSS percentile and public exploit research, though it requires authentication and user interaction and is not in KEV.
What it is
CVE-2019-0887 is a path traversal (CWE-22) flaw in Microsoft Remote Desktop Services that an authenticated attacker can abuse through clipboard redirection to achieve remote code execution. It matters because RDP clipboard sharing is widely enabled by default, and the flaw affects both the RDP client and a broad set of Windows client and server versions.
Impact
An authenticated attacker can write files outside the intended clipboard redirection directory and execute code on the target system, gaining the privileges of the affected process.
Attack surface
Reached over the network via an RDP session with clipboard redirection enabled; the attacker must be authenticated (PR:L) and some form of user interaction is required (UI:R) per the CVSS vector.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.70966, 99.37th percentile) and public technical descriptions exist from Check Point research, indicating meaningful exploitation interest.
What to do
- Apply the Microsoft security update referenced in the vendor advisory for CVE-2019-0887.
- Disable or restrict RDP clipboard redirection where it is not operationally required.
- Limit RDP exposure to trusted networks and require strong authentication for remote sessions.
- Monitor and restrict which accounts can initiate RDP sessions to reduce the authenticated attack surface.
Detection
- Alert on unexpected file creation or modification outside expected clipboard or temp directories during active RDP sessions.
- Monitor RDP session logs for clipboard redirection events correlated with suspicious process execution.
- Hunt for path traversal patterns in clipboard-related file paths on RDP hosts and clients.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/108964 | Broken LinkThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0887 | PatchVendor Advisory |
| https://research.checkpoint.com/reverse-rdp-attack-code-execution-on-rdp-clients/ | Technical DescriptionThird Party Advisory |
| https://research.checkpoint.com/reverse-rdp-the-hyper-v-connection/ | Technical DescriptionThird Party Advisory |
| http://www.securityfocus.com/bid/108964 | Broken LinkThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0887 | PatchVendor Advisory |
| https://research.checkpoint.com/reverse-rdp-attack-code-execution-on-rdp-clients/ | Technical DescriptionThird Party Advisory |
| https://research.checkpoint.com/reverse-rdp-the-hyper-v-connection/ | Technical DescriptionThird Party Advisory |
Track CVE-2019-0887 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-0887), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.