CVE detail
CVE-2019-0708
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
67 source links · newest first
FBI warns that North Korea–linked APT group Kimsuky is targeting governments, think tanks, and academic institutions with quishing attacks. North Korea–linked APT group Kimsuky is targeting government agencies, academic institutions, and think tanks using spear-phishing emails that contain malicious QR codes (quishing), the FBI warns. “As of 2025, Kimsuky actors have targeted think tanks, academic […]
newssecurityaffairs.comJan 10, 2026, 3:34 PM- Vulnerable vs. Exploitable: Why Understanding the Difference Matters to Your Security PostureHorizon3.ai
Scanning and patching aren’t enough. Learn the critical difference between being vulnerable and being exploitable—and why it’s the key to preventing real-world breaches.
exploithorizon3.aiJun 25, 2025, 1:00 PM The infamous BlueKeep flaw from 2019, tracked as CVE-2019-0708, has come back to haunt security professionals as reports of fresh, in-the-wild abuse surface. The dangerous, “wormable” RCE flaw affecting Microsoft’s remote desktop protocol (RDP) was exploited in a new campaign by North Korea-backed Kimsuky APT, targeting vulnerable South Korean and Japanese systems. South Korean cybersecurity […]
newswww.csoonline.comApr 22, 2025, 11:56 AMResearchers spotted a new North Korea-linked group Kimsuky ‘s campaign, exploiting a patched Microsoft Remote Desktop Services flaw to gain initial access. While investigating a security breach, the AhnLab SEcurity intelligence Center (ASEC) researchers discovered a North Korea-linked group Kimsuky ‘s campaign, tracked as Larva-24005. Attackers exploited an RDP vulnerability to gain initial access to […]
newssecurityaffairs.comApr 21, 2025, 6:25 PMResearchers discovered thousands of GitHub repositories that offer fake proof-of-concept (PoC) exploits for various flaws used to distribute malware. A team of researchers at the Leiden Institute of Advanced Computer Science (Soufian El Yadmani, Robin The, Olga Gadyatskaya) discovered thousands of repositories on GitHub that offer fake proof-of-concept (PoC) exploits for multiple vulnerabilities. The experts analyzed PoCs shared on […]
newssecurityaffairs.comOct 24, 2022, 7:24 AM- Defending against Windows RDP attacksHelp Net Security
In 2020, attacks against Windows Remote Desktop Protocol (RDP) grew by 768%, according to ESET. But this shouldn’t come as a surprise, given the massive increase in the number of people working remotely during the pandemic. With enterprises resorting to making RDP services publicly available, hackers have taken notice. Some DDoS attacks are leveraging RDP servers to amplify their effect, and malware like Trickbot is employing scanners to identify vulnerable open RDP ports. When it … More →
newswww.helpnetsecurity.comMay 10, 2021, 4:00 AM Network attack trends in the Winter quarter of 2020 revealed some interesting trends, such as increased attacker preference for newly released vulnerabilities and a large uptick in attacks deemed Critical. In addition to details of the newly observed exploits, in this blog, we also dive deep into the exploitation analysis, vendor analysis, attack origin, and attack category distribution.
vendorunit42.paloaltonetworks.comApr 12, 2021, 5:37 PMOrganizations in the financial and insurance sectors were the most targeted by threat actors in 2020, continuing a trend that was first observed roughly five years ago, IBM Security reports.
newswww.securityweek.comApr 2, 2021, 12:42 PM- Millions of devices could be hacked exploiting flaws targeted by tools stolen from FireEyeSecurity Affairs
Millions of devices are potential exposed to attacks targeting the vulnerabilities exploited by the tools stolen from the arsenal of FireEye. Security experts from Qualys are warning that more than 7.5 million devices are potentially exposed to cyber attacks targeting the vulnerabilities exploited by the tools stolen from the arsenal of FireEye. As a result […]
newssecurityaffairs.comDec 24, 2020, 7:15 PM Palo Alto Networks commends FireEye for transparency around its reported breach and is working to use the information shared to protect our customers.
vendorunit42.paloaltonetworks.comDec 11, 2020, 5:10 AMTo better protect Windows users, we discuss how attackers might exploit CVE-2019-0708 (BlueKeep) on Windows RDP endpoints.
vendorunit42.paloaltonetworks.comDec 7, 2020, 2:00 PM- 246869 Windows systems are still vulnerable to the BlueKeep flawSecurity Affairs
In May 2019, Microsoft disclosed the BlueKeep vulnerability, more than a year later over 245,000 Windows systems still remain unpatched. Over a year ago Microsoft Patch Tuesday updates for May 2019 addressed nearly 80 vulnerabilities, including the BlueKeep flaw. The issue is a remote code execution flaw in Remote Desktop Services (RDS) that can be exploited by […]
newssecurityaffairs.comNov 17, 2020, 12:03 PM The U.S. National Security Agency this week released an advisory containing information on 25 vulnerabilities that are being actively exploited or targeted by Chinese state-sponsored threat actors.
newswww.securityweek.comOct 21, 2020, 11:06 AM- 25 vulnerabilities exploited by Chinese state-sponsored hackersHelp Net Security
The US Cybersecurity and Infrastructure Security Agency (CISA) has released a list of 25 vulnerabilities Chinese state-sponsored hackers have been recently scanning for or have exploited in attacks. “Most of the vulnerabilities […] can be exploited to gain initial access to victim networks using products that are directly accessible from the Internet and act as gateways to internal networks. The majority of the products are either for remote access or for external web services, and … More →
newswww.helpnetsecurity.comOct 21, 2020, 10:23 AM - NSA details top 25 flaws exploited by China-linked hackersSecurity Affairs
The US National Security Agency (NSA) has shared the list of top 25 vulnerabilities exploited by Chinese state-sponsored hacking groups in attacks in the wild. The US National Security Agency (NSA) has published a report that includes details of the top 25 vulnerabilities that are currently being exploited by China-linked APT groups in attacks in the […]
newssecurityaffairs.comOct 20, 2020, 7:28 PM Researchers uncovered a recent campaign carried out by the InvisiMole group that has been targeting a small number of high-profile organizations. Security researchers at ESET recently uncovered a campaign carried out by the InvisiMole group that has been targeting a small number of high-profile organizations in the military sector and diplomatic missions in Eastern Europe. […]
newssecurityaffairs.comJun 18, 2020, 8:13 PMIn a recent campaign, the elusive InvisiMole group has been targeting a small number of high-profile organizations in the military sector and diplomatic missions in Eastern Europe, ESET reports.
newswww.securityweek.comJun 18, 2020, 11:12 AMEnterprises have been experimenting with work from home policies for years. Unfortunately, that experiment suddenly became the default this spring as local and state governments across the U.S. issued “stay at home” orders, leaving tens of millions of employees working from home for the first time. According to the CSO Pandemic Impact Survey, the number of employees working at least 60 percent of the time from home has increased five-fold since the institution of social … More →
newswww.helpnetsecurity.comJun 12, 2020, 5:00 AMUnit 42 researcher Tao Yan presented his findings in a closed-door session at BlueHat Seattle 2019 about advanced vulnerability exploitation technique, called Pool Feng Shui, and shared three new Windows RDP vulnerability exploitation methods.
vendorunit42.paloaltonetworks.comDec 12, 2019, 10:45 PMThe recent attacks exploiting the BlueKeep vulnerability to deliver cryptocurrency miners caused some systems to crash due to a Meltdown patch being deployed on the targeted machines.
newswww.securityweek.comNov 11, 2019, 12:09 PM- Australian Govt agency ACSC warns of Emotet and BlueKeep attacksSecurity Affairs
The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) warns businesses and netizens of Emotet and BlueKeep attacks in the wild. The ACSC is warning organizations and people of a wave of cyberattacks exploiting the Windows BlueKeep vulnerability to deliver crypto-currency miners. “The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC), with its state and territory partners, […]
newssecurityaffairs.comNov 11, 2019, 10:16 AM After news broke that cybercriminals have started leveraging the BlueKeep vulnerability to deliver cryptocurrency miners , Microsoft has warned that the exploit will likely also be used to deliver more “impactful and damaging” payloads.
newswww.securityweek.comNov 8, 2019, 5:14 PMMicrosoft is warning once again of more BlueKeep attacks that could deliver disruptive payloads and urges organizations to patch their systems. Recently, researchers warned of the first mass-hacking campaign exploiting the BlueKeep exploit, the attack aimed at installing a cryptocurrency miner on the infected systems. The popular expert Kevin Beaumont observed some of its EternalPot RDP honeypots crashing after being […]
newssecurityaffairs.comNov 8, 2019, 1:28 PM- 4th November – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 4th November 2019, please download our Threat Intelligence Bulletin. Top attacks AND breaches India’s nuclear power plant has been hit by a cyber-attack after malware designed for data extraction was identified in one of its systems. The malware, linked by experts to the North-Korean […]
vendorresearch.checkpoint.comNov 4, 2019, 11:52 AM The notorious Windows Remote Desktop Services (RDS) vulnerability tracked as CVE-2019-0708 and BlueKeep has been exploited in the wild to deliver cryptocurrency mining malware, researchers warned over the weekend.
newswww.securityweek.comNov 4, 2019, 9:53 AMExperts have spotted the first mass-hacking campaign exploiting the BlueKeep exploit, crooks leverage the exploit to install a cryptocurrency miner. Security researchers have spotted the first mass-hacking campaign exploiting the BlueKeep exploit, the attack aims at installing a cryptocurrency miner on the infected systems. In May, Microsoft warned users to update their systems to address […]
newssecurityaffairs.comNov 3, 2019, 2:21 PM- 9th September – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 9th September 2019, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Attackers have convinced the CEO of an energy company to send $243,000 to a fake supplier using AI to create a deep fake voice impersonation of a chief executive. “Joker”, […]
vendorresearch.checkpoint.comSep 9, 2019, 3:39 PM - BlueKeep Exploit Added to MetasploitSecurityWeek
An initial public exploit targeting the recently addressed BlueKeep vulnerability in Microsoft Windows has been added to Rapid7’s Metasploit framework.
newswww.securityweek.comSep 9, 2019, 1:57 PM - Experts add a BlueKeep exploit module to MetaSploitSecurity Affairs
Maintainers of the open-source Metasploit penetration testing framework have added a public exploit module for the BlueKeep Windows flaw. There is a surprise for Metasploit users, maintainers of the open-source penetration testing framework have added a public exploit module for the BlueKeep Windows flaw. The BlueKeep vulnerability, tracked as CVE-2019-0708, impacts the Windows Remote Desktop Services (RDS) and was addressed by Microsoft […]
newssecurityaffairs.comSep 7, 2019, 2:36 PM - Exploitation of Windows CVE-2019-0708 (BlueKeep): Three Ways to Write Data into Kernel with RDP PDUUnit42
Executive Summary In May 2019, Microsoft released an out-of-band patch update for remote code execution vulnerability CVE-2019-0708, which is also known as “BlueKeep” and resides in code to Remote Desktop Services (RDS). This vulnerability is pre-authentication and requires no user interaction, making it particularly dangerous as it has the unsettling potential to be weaponized into
vendorunit42.paloaltonetworks.comAug 29, 2019, 1:00 PM - How to avoid using RDP on WindowsCSO Online
The recent discovery of several security vulnerabilities targeting Remote Desktop Protocol (RDP) has led to warnings that we should immediately patch Windows. CVE-2019-0708 (BlueKeep), CVE-2019-1181 (BlueKeep II), and CVE-2019-1182 (BlueKeep III) all rely on the fact that many admins still set up servers and leave them open to remote access over the internet. Reviewing what […]
newswww.csoonline.comAug 21, 2019, 10:00 AM Microsoft has identified and patched several vulnerabilities in the Windows Remote Desktop Services (RDS) component — formerly known as Terminal Services — which is widely used in corporate environments to remotely manage Windows machines. Some of the vulnerabilities can be exploited without authentication to achieve remote code execution and full system compromise, making them highly […]
newswww.csoonline.comAug 14, 2019, 11:55 PMMicrosoft’s latest security updates patch more wormable vulnerabilities related to Remote Desktop Services (RDS) and the company has published a blog post to warn users about the risk they pose.
newswww.securityweek.comAug 14, 2019, 1:33 PMMore than 750,000 systems remain vulnerable to the BlueKeep vulnerability as patching rate has decreased by around 85%, a new report from security firm BitSight reveals.
newswww.securityweek.comAug 14, 2019, 4:57 AM- New variant of Linux Botnet WatchBog adds BlueKeep scannerSecurity Affairs
Experts at Intezer researchers have spotted a strain of the Linux mining that also scans the Internet for Windows RDP servers vulnerable to the Bluekeep. Researchers at Intezer have discovered a new variant of WatchBog, a Linux-based cryptocurrency mining botnet, that also includes a module to scan the Internet for Windows RDP servers vulnerable to the Bluekeep vulnerability (CVE-2019-0708). […]
newssecurityaffairs.comJul 25, 2019, 3:17 PM - Thwart the pressing threat of RDP password attacksHelp Net Security
How long does it takes for Internet-facing, RDP-enabled computers to come under attack? In some cases, a few minutes. In most, less than 24 hours. The problem with RDP “In recent years, criminals deploying targeted ransomware like BitPaymer, Ryuk, Matrix, and SamSam have almost completely abandoned other methods of network ingress in favor of using RDP,” say Sophos researchers Matt Boddy, Ben Jones, and Mark Stockley. “Gangs like these have the choice cracking passwords themselves … More →
newswww.helpnetsecurity.comJul 23, 2019, 9:54 AM Users and organizations continue to patch the Windows vulnerability tracked as BlueKeep and CVE-2019-0708 , but over 800,000 systems are still exposed to attacks.
newswww.securityweek.comJul 18, 2019, 5:03 PM- DHS also issued an alert for the Windows BlueKeep flawSecurity Affairs
The Cybersecurity and Infrastructure Security Agency (CISA) of the U.S. DHS on Monday issued an alert for the BlueKeep Windows flaw (CVE-2019-0708). After Microsoft and the US NSA, the Cybersecurity and Infrastructure Security Agency (CISA) of the U.S. DHS on Monday issued an alert for the BlueKeep Windows flaw (CVE-2019-0708). Experts at the CISA Agency successfully […]
newssecurityaffairs.comJun 18, 2019, 8:45 AM The Cybersecurity and Infrastructure Security Agency (CISA) of the U.S. Department of Homeland Security (DHS) on Monday issued an alert for the Windows vulnerability tracked as BlueKeep and CVE-2019-0708.
newswww.securityweek.comJun 17, 2019, 6:07 PMA new piece of malware is targeting Windows severs with the remote desktop protocol (RDP) exposed to the Internet with the intent to ensnare them into a massive botnet, SANS ISC warns.
newswww.securityweek.comJun 10, 2019, 3:09 PMHere’s an overview of some of last week’s most interesting news and articles: Apple debuts privacy-minded “Sign in with Apple” SSO Apple’s new single sign-on (SSO) authentication mechanism is similar to the one provided by Facebook, Google, LinkedIn, Twitter, and others, in that it will allow users to sign in to apps and websites without creating a new account. But there are important differences, mainly focused on assuring users’ privacy. June Patch Tuesday forecast: Apply … More →
newswww.helpnetsecurity.comJun 9, 2019, 6:00 PMCan you believe it is June already? Summer is rapidly approaching, but it’s been slow to warm up our temperatures here in the US. I can’t say the same thing about the temperature in our security community – things have been hot! The first months of 2019 have seen a record number of vulnerabilities reported and the latest, BlueKeep associated with CVE-2019-0708, has set the forums and security advisory lists on fire. The May updates … More →
newswww.helpnetsecurity.comJun 7, 2019, 9:30 AM- NSA urges Windows Users and admins to Patch BlueKeep flawSecurity Affairs
The National Security Agency (NSA) is urging Windows users and administrators to install security updates to address BlueKeep flaw (aka CVE-2019-0708). Last week Microsoft issued a second security advisory to warn users of older Windows OS versions to update their systems in order to patch the remote code execution vulnerability dubbed BlueKeep. Now the National Security […]
newssecurityaffairs.comJun 5, 2019, 2:10 PM The U.S. National Security Agency (NSA) on Tuesday urged Windows users and administrators to immediately address the vulnerability tracked as BlueKeep and CVE-2019-0708.
newswww.securityweek.comJun 5, 2019, 12:54 PM- Expert developed a MetaSploit module for the BlueKeep flawSecurity Affairs
A security expert has developed a Metasploit module to exploit the critical BlueKeep vulnerability and get remote code execution. The security researcher Zǝɹosum0x0 has developed a module for the popular Metasploit penetration testing framework to exploit the critical BlueKeep flaw. The vulnerability, tracked as CVE-2019-0708, impacts the Windows Remote Desktop Services (RDS) and was addressed by Microsoft with May […]
newssecurityaffairs.comJun 5, 2019, 8:30 AM The Network Level Authentication (NLA) feature of Windows Remote Desktop Services (RDS) can allow a hacker to bypass the lockscreen on remote sessions, and there is no patch from Microsoft, the CERT Coordination Center at Carnegie Mellon University warned on Tuesday.
newswww.securityweek.comJun 4, 2019, 5:39 PM- 3rd June – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 3rd June 2019, please download our Threat Intelligence Bulletin TOP ATTACKS AND BREACHES Around 855 million of insurance-related documents have been leaked online after the US real-estate insurance company First American Financial Corp. accidentally left the documents unsecured on their website. The leaked […]
vendorresearch.checkpoint.comJun 3, 2019, 8:11 PM - Microsoft warns for the second time of applying BlueKeep patchSecurity Affairs
Microsoft issued a new warning for users to update their systems to address the remote code execution vulnerability dubbed BlueKeep. Microsoft issued a new warning for users of older Windows OS versions to update their systems in order to patch the remote code execution vulnerability dubbed BlueKeep. The vulnerability, tracked as CVE-2019-0708, impacts the Windows […]
newssecurityaffairs.comMay 31, 2019, 2:26 PM Microsoft has reminded users to patch the Windows vulnerability tracked as BlueKeep and CVE-2019-0708 due to the high risk of exploitation.
newswww.securityweek.comMay 31, 2019, 2:13 PMTwo weeks have passed since Microsoft released security fixes and mitigation advice to defang exploits taking advantage of CVE-2019-0708 (aka BlueKeep), a wormable unauthenticated remote code execution flaw in Remote Desktop Services (RDP). The vulnerability, reported by UK’s National Cyber Security Centre (NCSC), has the potential to be the means for attacks that could rival the 2017 WannaCry onslaught in size and effect. A recent scanning effort by Robert Graham, head of offensive security research … More →
newswww.helpnetsecurity.comMay 29, 2019, 10:09 AMRoughly one million devices are vulnerable to attacks exploiting the BlueKeep Windows vulnerability and hackers are ready to hit them. Yesterday I reported the discovery made by experts at GreyNoise that detected scans for systems vulnerable to the BlueKeep (CVE-2019-0708) vulnerability. The scans were first detected on May 25, 2019, experts explained that a single […]
newssecurityaffairs.comMay 28, 2019, 7:48 PMNearly one million devices are vulnerable to attacks involving the Windows vulnerability dubbed BlueKeep and it appears that hackers have already started scanning the web in search of potential targets.
newswww.securityweek.comMay 28, 2019, 2:39 PMSeveral products made by Siemens Healthineers are affected by a recently patched Windows BlueKeep vulnerability (CVE-2019-0708). The BlueKeep issue is a remote code execution vulnerability in Remote Desktop Services (RDS) that it can be exploited by an unauthenticated attacker by connecting to the targeted system via the RDP and sending specially crafted requests. As explained by […]
newssecurityaffairs.comMay 28, 2019, 11:11 AMSeveral products made by Siemens Healthineers, a Siemens company that specializes in medical technology, are affected by a recently patched Windows vulnerability tracked as CVE-2019-0708 and BlueKeep.
newswww.securityweek.comMay 28, 2019, 5:40 AM- BlueKeep scans observed from exclusively Tor exit nodesSecurity Affairs
GreyNoise experts detected scans for systems vulnerable to the BlueKeep (CVE-2019-0708) vulnerability from exclusively Tor exit nodes. Microsoft Patch Tuesday updates for May 2019 address nearly 80 vulnerabilities, including an RDS vulnerability dubbed BlueKeep that can be exploited to carry out WannaCry-like attack. The issue is a remote code execution flaw in Remote Desktop Services (RDS) that it can […]
newssecurityaffairs.comMay 27, 2019, 4:53 PM - Security Affairs newsletter Round 215 – News of the weekSecurity Affairs
A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Kindle Edition Paper Copy If you appreciate my effort in spreading cybersecurity awareness, please vote for Security Affairs in the section “Your Vote for the Best EU Security Tweeter” https://www.surveymonkey.com/r/EUBloggerAwards2018 Dutch intelligence investigate alleged Huawei ‘backdoor Salesforce […]
newssecurityaffairs.comMay 26, 2019, 12:39 PM Several security experts have developed PoC exploits for wormable Windows RDS flaw tracked as CVE-2019-0708 and dubbed BlueKeep. Experts have developed several proof-of-concept (PoC) exploits for the recently patched Windows Remote Desktop Services (RDS) vulnerability tracked as CVE-2019-0708 and dubbed BlueKeep. One of the PoC exploits could be used for remote code execution on vulnerable […]
newssecurityaffairs.comMay 23, 2019, 10:37 PMSeveral proof-of-concept (PoC) exploits, including ones that can be used for remote code execution, have been developed for the recently patched Windows Remote Desktop Services (RDS) vulnerability tracked as CVE-2019-0708 and dubbed BlueKeep.
newswww.securityweek.comMay 23, 2019, 12:52 PM- If you haven’t yet patched the BlueKeep RDP vulnerability, do so nowHelp Net Security
There is still no public, working exploit code for CVE-2019-0708, a flaw that could allow an unauthenticated remote attacker to execute remote code on a vulnerable target running Remote Desktop Protocol (RDP). But, as many infosec experts have noted, we’re not far off from when one is created and leveraged by attackers in the wild. With the vulnerability being wormable, when it hits, the exploit could end up compromising millions of systems around the world, … More →
newswww.helpnetsecurity.comMay 23, 2019, 10:36 AM Sophos is warning users of potential problems with the recent Microsoft’s Patch Tuesday updates and is saying to roll back it if they want the PC to boot. The security firm has informed its customers of potential problems with the latest Microsoft’s Patch Tuesday updates and is asking them to uninstall the patch if they […]
newssecurityaffairs.comMay 21, 2019, 2:46 PM- Microsoft updates break AV software, again!Help Net Security
Microsoft’s May 2019 security fixes have again disrupted the normal functioning of some endpoint security products on certain Windows versions. Current problems “We have had a few customers reporting that following on from the Microsoft Windows 14th May patches they are experiencing a hang on boot where the machines appear to get stuck on ‘Configuring 30%’,” UK-based Sophos explained. “We have currently only identified the issue on a few customers running Windows 7 and Windows … More →
newswww.helpnetsecurity.comMay 21, 2019, 9:24 AM Here’s an overview of some of last week’s most interesting news and articles: High-risk vulnerability in Cisco’s secure boot process impacts millions of devices Red Balloon Security has discovered a high-risk vulnerability in Cisco’s secure boot process which impacts a wide range of Cisco products in use among enterprise and government networks, including routers, switches and firewalls. Tips to spring clean your company’s social media and stay protected Spring is a great time for organizations … More →
newswww.helpnetsecurity.comMay 19, 2019, 5:00 PMA critical remote code execution vulnerability patched recently by Microsoft in Windows Remote Desktop Services (RDS) poses a serious risk to industrial environments, experts have warned.
newswww.securityweek.comMay 17, 2019, 12:34 PMMicrosoft has fixed a critical vulnerability in some versions of Windows that can be exploited to create a powerful worm. The company even took the unusual step of releasing patches for Windows XP and Windows Server 2003, which haven’t been supported in years, because it believes the threat to be very high. The vulnerability, tracked […]
newswww.csoonline.comMay 15, 2019, 4:46 PM- Microsoft Patch Tuesday addresses dangerous RDS flaw that opens to WannaCry-like attacksSecurity Affairs
Microsoft Patch Tuesday updates for May 2019 address nearly 80 vulnerabilities, including an RDS flaw allowing WannaCry-Like attacks. Microsoft Patch Tuesday updates for May 2019 address nearly 80 vulnerabilities, including a Windows zero-day flaw and an RDS vulnerability that can be exploited to carry out WannaCry-like attack. The zero-day vulnerability addressed by Microsoft Patch Tuesday […]
newssecurityaffairs.comMay 15, 2019, 12:57 PM - Microsoft plugs wormable RDP flaw, new speculative execution side channel vulnerabilitiesHelp Net Security
For May 2019 Patch Tuesday, Microsoft has released fixes for 79 vulnerabilities, 22 of which are deemed critical. Among the fixes is that for CVE-2019-0708, a “wormable” RDP flaw that is expected to be weaponised by attackers very soon. About CVE-2019-0708 It’s a remote code execution vulnerability in Remote Desktop Services (formerly known as Terminal Services) that allows unauthenticated attackers to connect to the target system using RDP and send specially crafted requests. The flaw … More →
newswww.helpnetsecurity.comMay 15, 2019, 9:33 AM Microsoft’s Patch Tuesday updates for May 2019 address nearly 80 vulnerabilities, including a zero-day and a flaw that can be exploited by malware to spread similar to the way the notorious WannaCry did back in 2017.
newswww.securityweek.comMay 15, 2019, 6:06 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-21774CVSS 7.8 · High
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-21773CVSS 7.8 · High
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-21755CVSS 7.8 · High
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-21747CVSS 7.8 · High
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-21680CVSS 7.8 · High
Windows Win32k Elevation of Privilege Vulnerability
- CVE-2023-21679CVSS 8.1 · High
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability