CVE-2019-0708
CRITICALA remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP…
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Description
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
Affected Products
agile controller-campus firmwarehuaweibh620 v2 firmwarehuaweibh621 v2 firmwarehuaweibh622 v2 firmwarehuaweibh640 v2 firmwarehuaweich121 firmwarehuaweiResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
Microsoft Windows 7 (x86) - 'BlueKeep' Remote Desktop Protocol (RDP) Remote Windows Kernel Use After Free
by 0xeb-bp · Nov 19, 2019
Microsoft Windows - BlueKeep RDP Remote Windows Kernel Use After Free (Metasploit)
by Metasploit · Sep 24, 2019
Microsoft Windows Remote Desktop - 'BlueKeep' Denial of Service (Metasploit)
by RAMELLA Sebastien · Jul 15, 2019
Microsoft Windows Remote Desktop - 'BlueKeep' Denial of Service
by n1xbyte · May 30, 2019
Frequently Asked Questions
Is CVE-2019-0708 in your stack?
O3 detects CVE-2019-0708 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.