Microsoft Remote Desktop Services Remote Code Execution Vulnerability

Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.

Published 23 Aug 2026Updated 23 Aug 2026128 sources
CVSS 0.0 ✓ VERIFIED REFERENCE△ CISA KEV

What happened

Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.

Affected versions

Remote Desktop Services: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 46946Microsoft Windows Remote Desktop - 'BlueKeep' Denial of Servicen1xbyte2019-05-30VerifiedExploit-DB 47120Microsoft Windows Remote Desktop - 'BlueKeep' Denial of Service (Metasploit)RAMELLA Sebastien2019-07-15VerifiedExploit-DB 47416Microsoft Windows - BlueKeep RDP Remote Windows Kernel Use After Free (Metasploit)Metasploit2019-09-24VerifiedExploit-DB 47683Microsoft Windows 7 (x86) - 'BlueKeep' Remote Desktop Protocol (RDP) Remote Windows Kernel Use After Free0xeb-bp2019-11-19VerifiedPoC-in-GitHub · hook-s3c/CVE-2019-0708-pocproof of concept exploit for Microsoft Windows 7 and Server 2008 RDP vulnerability★ 47hook-s3c2019-05-14CandidatePoC-in-GitHub · SherlockSec/CVE-2019-0708A Win7 RDP exploit★ 13SherlockSec2019-05-14CandidatePoC-in-GitHub · yetiddbb/CVE-2019-0708-PoCCVE-2019-0708★ 0yetiddbb2019-05-15CandidatePoC-in-GitHub · p0p0p0/CVE-2019-0708-exploitCVE-2019-0708-exploit★ 121p0p0p02019-05-15CandidatePoC-in-GitHub · rockmelodies/CVE-2019-0708-ExploitUsing CVE-2019-0708 to Locally Promote Privileges in Windows 10 System★ 31rockmelodies2019-05-15CandidatePoC-in-GitHub · anquanscan/CVE-2019-0708CVE-2019-0708 exp★ 9anquanscan2019-05-15CandidatePoC-in-GitHub · temp-user-2014/CVE-2019-0708CVE-2019-0708★ 1temp-user-20142019-05-15CandidatePoC-in-GitHub · areusecure/CVE-2019-0708Proof of concept exploit for CVE-2019-0708★ 3areusecure2019-05-15CandidatePoC-in-GitHub · pry0cc/cve-2019-0708-2Testing my new bot out★ 3pry0cc2019-05-15CandidatePoC-in-GitHub · sbkcbig/CVE-2019-0708-EXPloitPOCexp:https://pan.baidu.com/s/184gN1tJVIOYqOjaezM_VsA 提取码:e2k8★ 1sbkcbig2019-05-15CandidatePoC-in-GitHub · sbkcbig/CVE-2019-0708-EXPloit-3389EXPloit-poc: https://pan.baidu.com/s/184gN1tJVIOYqOjaezM_VsA 提取码:e2k8★ 0sbkcbig2019-05-15CandidatePoC-in-GitHub · YSheldon/MS_T120CVE-2019-0708★ 1YSheldon2019-05-15CandidatePoC-in-GitHub · k8gege/CVE-2019-07083389远程桌面代码执行漏洞CVE-2019-0708批量检测工具(Rdpscan Bluekeep Check)★ 388k8gege2019-05-15CandidatePoC-in-GitHub · hotdog777714/RDS_CVE-2019-0708exploit CVE-2019-0708 RDS★ 1hotdog7777142019-05-15CandidatePoC-in-GitHub · jiansiting/CVE-2019-0708RDP POC★ 19jiansiting2019-05-15CandidatePoC-in-GitHub · NullByteSuiteDevs/CVE-2019-0708PoC exploit for BlueKeep (CVE-2019-0708)★ 6NullByteSuiteDevs2019-05-15CandidatePoC-in-GitHub · thugcrowd/CVE-2019-0708sup pry0cc :3★ 7thugcrowd2019-05-15CandidatePoC-in-GitHub · blacksunwen/CVE-2019-0708CVE-2019-0708★ 19blacksunwen2019-05-15CandidatePoC-in-GitHub · infenet/CVE-2019-0708★ 2infenet2019-05-15CandidatePoC-in-GitHub · n0auth/CVE-2019-0708Totally legitimate★ 11n0auth2019-05-15CandidatePoC-in-GitHub · gildaaa/CVE-2019-0708★ 1gildaaa2019-05-15CandidatePoC-in-GitHub · HackerJ0e/CVE-2019-0708★ 1HackerJ0e2019-05-15CandidatePoC-in-GitHub · syriusbughunt/CVE-2019-0708PoC about CVE-2019-0708 (RDP; Windows 7, Windows Server 2003, Windows Server 2008)★ 39syriusbughunt2019-05-16CandidatePoC-in-GitHub · Barry-McCockiner/CVE-2019-0708A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.★ 1Barry-McCockiner2019-05-16CandidatePoC-in-GitHub · ShadowBrokers-ExploitLeak/CVE-2019-0708A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.★ 2ShadowBrokers-ExploitLeak2019-05-16CandidatePoC-in-GitHub · safly/CVE-2019-0708CVE-2019-0708 demo★ 1safly2019-05-16CandidatePoC-in-GitHub · Jaky5155/cve-2019-0708-exp★ 30Jaky51552019-05-16CandidatePoC-in-GitHub · fourtwizzy/CVE-2019-0708-Check-Device-Patch-StatusPowershell script to run and determine if a specific device has been patched for CVE-2019-0708. This checks to see if the termdd.sys file has been updated appropriate and is at a version level at or greater than the versions released in the 5/14/19 patches.★ 18fourtwizzy2019-05-16CandidatePoC-in-GitHub · 303sec/CVE-2019-0708POC for CVE-2019-0708★ 1303sec2019-05-16CandidatePoC-in-GitHub · f8al/CVE-2019-0708-POCPoC for CVE-2019-0708★ 0f8al2019-05-16CandidatePoC-in-GitHub · blockchainguard/CVE-2019-0708CVE-2019-0708漏洞MSF批量巡检插件★ 5blockchainguard2019-05-17CandidatePoC-in-GitHub · yushiro/CVE-2019-0708LOL★ 1yushiro2019-05-18CandidatePoC-in-GitHub · skyshell20082008/CVE-2019-0708-PoC-Hitting-PathIt's only hitting vulnerable path in termdd.sys!!! NOT DOS★ 12skyshell200820082019-05-19CandidatePoC-in-GitHub · ttsite/CVE-2019-0708-Announces fraud★ 2ttsite2019-05-20CandidatePoC-in-GitHub · ttsite/CVE-2019-0708Report fraud★ 1ttsite2019-05-21CandidatePoC-in-GitHub · biggerwing/CVE-2019-0708-pocCVE-2019-0708 远程代码执行漏洞批量检测★ 82biggerwing2019-05-21CandidatePoC-in-GitHub · n1xbyte/CVE-2019-0708dump★ 496n1xbyte2019-05-21CandidatePoC-in-GitHub · freeide/CVE-2019-0708High level exploit★ 1freeide2019-05-21CandidatePoC-in-GitHub · edvacco/CVE-2019-0708-POC根据360的程序,整的CVE-2019-0708批量检测★ 2edvacco2019-05-21CandidatePoC-in-GitHub · pry0cc/BlueKeepTrackerMy bot (badly written) to search and monitor cve-2019-0708 repositories★ 4pry0cc2019-05-21CandidatePoC-in-GitHub · zjw88282740/CVE-2019-0708-win7★ 1zjw882827402019-05-21CandidatePoC-in-GitHub · victor0013/CVE-2019-0708Scanner PoC for CVE-2019-0708 RDP RCE vuln★ 3victor00132019-05-22CandidatePoC-in-GitHub · herhe/CVE-2019-0708poc根据360Vulcan Team开发的CVE-2019-0708单个IP检测工具构造了个批量检测脚本而已★ 1herhe2019-05-22CandidatePoC-in-GitHub · major203/cve-2019-0708-scan★ 6major2032019-05-22CandidatePoC-in-GitHub · SugiB3o/Check-vuln-CVE-2019-0708Check vuln CVE 2019-0708★ 7SugiB3o2019-05-23CandidatePoC-in-GitHub · gobysec/CVE-2019-0708Goby support CVE-2019-0708 "BlueKeep" vulnerability check★ 17gobysec2019-05-23CandidatePoC-in-GitHub · smallFunction/CVE-2019-0708-POCWorking proof of concept for CVE-2019-0708, spawns remote shell.★ 2smallFunction2019-05-23CandidatePoC-in-GitHub · freeide/CVE-2019-0708-PoC-ExploitCVE-2019-0708 PoC Exploit★ 0freeide2019-05-23CandidatePoC-in-GitHub · robertdavidgraham/rdpscanA quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability.★ 921robertdavidgraham2019-05-23CandidatePoC-in-GitHub · closethe/CVE-2019-0708-POCcve-2019-0708 poc .★ 13closethe2019-05-24CandidatePoC-in-GitHub · SQLDebugger/CVE-2019-0708-Tool50 first stargazers will get get the tool via email★ 0SQLDebugger2019-05-24CandidatePoC-in-GitHub · Leoid/CVE-2019-0708Only Hitting PoC [Tested on Windows Server 2008 r2]★ 126Leoid2019-05-28CandidatePoC-in-GitHub · ht0Ruial/CVE-2019-0708Poc-BatchScanning基于360公开的无损检测工具的可直接在windows上运行的批量检测程序★ 5ht0Ruial2019-05-28CandidatePoC-in-GitHub · oneoy/BlueKeepCVE-2019-0708 bluekeep 漏洞检测★ 0oneoy2019-05-29CandidatePoC-in-GitHub · infiniti-team/CVE-2019-0708★ 6infiniti-team2019-05-29CandidatePoC-in-GitHub · haishanzheng/CVE-2019-0708-generate-hosts★ 2haishanzheng2019-05-29CandidatePoC-in-GitHub · Ekultek/BlueKeepProof of concept for CVE-2019-0708★ 1182Ekultek2019-05-29CandidatePoC-in-GitHub · UraSecTeam/CVE-2019-0708CVE-2019-0708★ 1UraSecTeam2019-05-30CandidatePoC-in-GitHub · Gh0st0ne/rdpscan-BlueKeepA quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability.★ 1Gh0st0ne2019-05-30CandidatePoC-in-GitHub · algo7/bluekeep_CVE-2019-0708_poc_to_exploitAn Attempt to Port BlueKeep PoC from @Ekultek to actual exploits★ 342algo72019-05-31CandidatePoC-in-GitHub · JasonLOU/CVE-2019-0708★ 1JasonLOU2019-05-31CandidatePoC-in-GitHub · AdministratorGithub/CVE-2019-0708CVE-2019-0708批量蓝屏恶搞★ 1AdministratorGithub2019-05-31CandidatePoC-in-GitHub · umarfarook882/CVE-2019-0708CVE-2019-0708 - BlueKeep (RDP)★ 40umarfarook8822019-05-31CandidatePoC-in-GitHub · HynekPetrak/detect_bluekeep.pyPython script to detect bluekeep vulnerability (CVE-2019-0708) with TLS/SSL and x509 support★ 27HynekPetrak2019-06-03CandidatePoC-in-GitHub · Pa55w0rd/CVE-2019-0708CVE-2019-0708批量检测★ 13Pa55w0rd2019-06-11CandidatePoC-in-GitHub · zoujialan/CVE-2019-0708-RCECVE-2019-0708-RCE★ 0zoujialan2019-06-12CandidatePoC-in-GitHub · cream-sec/CVE-2019-0708-Msf--CVE-2019-0708-Msf-验证★ 1cream-sec2019-06-12CandidatePoC-in-GitHub · ZhaoYukai/CVE-2019-0708蓝屏poc★ 0ZhaoYukai2019-06-13CandidatePoC-in-GitHub · ZhaoYukai/CVE-2019-0708-Batch-Blue-Screen改写某大佬写的0708蓝屏脚本 改为网段批量蓝屏★ 0ZhaoYukai2019-06-13CandidatePoC-in-GitHub · wdfcc/CVE-2019-0708★ 1wdfcc2019-06-20CandidatePoC-in-GitHub · cvencoder/cve-2019-0708POC CVE-2019-0708 with python script!★ 14cvencoder2019-06-24CandidatePoC-in-GitHub · ze0r/CVE-2019-0708-exp★ 12ze0r2019-07-04CandidatePoC-in-GitHub · mekhalleh/cve-2019-0708Metasploit module for massive Denial of Service using #Bluekeep vector.★ 23mekhalleh2019-07-14CandidatePoC-in-GitHub · cve-2019-0708-poc/cve-2019-0708CVE-2019-0708 Exploit Tool★ 18cve-2019-0708-poc2019-07-18CandidatePoC-in-GitHub · benhe119/bluekeepscanCVE-2019-0708★ 0benhe1192019-07-18CandidatePoC-in-GitHub · andripwn/CVE-2019-0708Scanner PoC for CVE-2019-0708 RDP RCE vuln★ 3andripwn2019-07-18CandidatePoC-in-GitHub · 0xeb-bp/bluekeepPublic work for CVE-2019-0708★ 2930xeb-bp2019-07-23CandidatePoC-in-GitHub · ntkernel0/CVE-2019-0708收集网上CVE-2018-0708的poc和exp(目前没有找到exp)★ 1ntkernel02019-07-25CandidatePoC-in-GitHub · dorkerdevil/Remote-Desktop-Services-Remote-Code-Execution-Vulnerability-CVE-2019-0708-rce exploit , made to work with pocsuite3★ 123dorkerdevil2019-08-17CandidatePoC-in-GitHub · turingcompl33t/bluekeepResearch Regarding CVE-2019-0708.★ 4turingcompl33t2019-08-18CandidatePoC-in-GitHub · skommando/CVE-2019-0708CVE-2019-0708 BlueKeep漏洞批量扫描工具和POC,暂时只有蓝屏。★ 2skommando2019-09-03CandidatePoC-in-GitHub · RickGeex/msf-module-CVE-2019-0708Metasploit module for CVE-2019-0708 (BlueKeep) - https://github.com/rapid7/metasploit-framework/tree/5a0119b04309c8e61b44763ac08811cd3ecbbf8d/modules/exploits/windows/rdp★ 13RickGeex2019-09-06CandidatePoC-in-GitHub · wqsemc/CVE-2019-0708initial exploit for CVE-2019-0708, BlueKeep CVE-2019-0708 BlueKeep RDP Remote Windows Kernel Use After Free The RDP termdd.sys driver improperly handles binds to internal-only channel MS_T120, allowing a malformed Disconnect Provider Indication message to cause use-after-free. With a controllable data/size remote nonpaged pool spray, an indirect call gadget of the freed channel is used to achieve arbitrary code execution.★ 12wqsemc2019-09-07CandidatePoC-in-GitHub · FrostsaberX/CVE-2019-0708CVE-2019-0708 With Metasploit-Framework Exploit★ 4FrostsaberX2019-09-07CandidatePoC-in-GitHub · 0x6b7966/CVE-2019-0708-RCECVE-2019-0708 RCE远程代码执行getshell教程★ 10x6b79662019-09-07CandidatePoC-in-GitHub · qing-root/CVE-2019-0708-EXP-MSF-CVE-2019-0708-EXP(MSF) Vulnerability exploit program for cve-2019-0708★ 11qing-root2019-09-07CandidatePoC-in-GitHub · distance-vector/CVE-2019-0708★ 1distance-vector2019-09-11CandidatePoC-in-GitHub · 0xFlag/CVE-2019-0708-testCVE-2019-0708 C#验证漏洞★ 10xFlag2019-09-11CandidatePoC-in-GitHub · 1aa87148377/CVE-2019-0708★ 11aa871483772019-09-17CandidatePoC-in-GitHub · coolboy4me/cve-2019-0708_bluekeep_rceit works on xp (all version sp2 sp3)★ 75coolboy4me2019-09-29CandidatePoC-in-GitHub · Cyb0r9/ispyispy V1.0 - Eternalblue(ms17-010)/Bluekeep(CVE-2019-0708) Scanner and exploit ( Metasploit automation )★ 245Cyb0r92019-09-30CandidatePoC-in-GitHub · ulisesrc/-2-CVE-2019-0708★ 1ulisesrc2019-11-22CandidatePoC-in-GitHub · worawit/CVE-2019-0708CVE-2019-0708 (BlueKeep)★ 109worawit2019-12-07CandidatePoC-in-GitHub · Ameg-yag/WincrashMass exploit for CVE-2019-0708★ 0Ameg-yag2019-12-20CandidatePoC-in-GitHub · cbwang505/CVE-2019-0708-EXP-WindowsCVE-2019-0708-EXP-Windows版单文件exe版,运行后直接在当前控制台反弹System权限Shell★ 317cbwang5052020-01-21CandidatePoC-in-GitHub · eastmountyxz/CVE-2019-0708-Windows这篇文章将分享Windows远程桌面服务漏洞(CVE-2019-0708),并详细讲解该漏洞及防御措施。作者作为网络安全的小白,分享一些自学基础教程给大家,主要是关于安全工具和实践操作的在线笔记,希望您们喜欢。同时,更希望您能与我一起操作和进步,后续将深入学习网络安全和系统安全知识并分享相关实验。总之,希望该系列文章对博友有所帮助,写文不易,大神们不喜勿喷,谢谢!★ 5eastmountyxz2020-02-19CandidatePoC-in-GitHub · RICSecLab/CVE-2019-0708CVE-2019-0708 (BlueKeep) proof of concept allowing pre-auth RCE on Windows7★ 148RICSecLab2020-03-15CandidatePoC-in-GitHub · JSec1337/Scanner-CVE-2019-0708Scanner CVE-2019-0708★ 1JSec13372020-03-17CandidatePoC-in-GitHub · nochemax/bLuEkEeP-GUIvulnerabilidad CVE-2019-0708 testing y explotacion★ 1nochemax2020-05-23CandidatePoC-in-GitHub · AaronCaiii/CVE-2019-0708-POC★ 0AaronCaiii2020-11-06CandidatePoC-in-GitHub · DeathStroke-source/Mass-scanner-for-CVE-2019-0708-RDP-RCE-ExploitScan through given ip list★ 1DeathStroke-source2020-12-03CandidatePoC-in-GitHub · ryan-ally/rdp0708scannercve-2019-0708 vulnerablility scanner★ 0ryan-ally2020-12-17CandidatePoC-in-GitHub · sezayi1972/CVE-2019-0708CVE-2019-0708 Exploit★ 0sezayi19722021-04-03CandidatePoC-in-GitHub · CircuitSoul/CVE-2019-0708POC-CVE-2019-0708★ 1CircuitSoul2021-06-19CandidatePoC-in-GitHub · pywc/CVE-2019-0708★ 0pywc2021-06-21CandidatePoC-in-GitHub · bibo318/kali-CVE-2019-0708-lab★ 0bibo3182021-10-19CandidatePoC-in-GitHub · lisinan988/CVE-2019-0708-scan★ 0lisinan9882021-11-25CandidatePoC-in-GitHub · offensity/CVE-2019-0708★ 0offensity2021-12-20CandidatePoC-in-GitHub · Ravaan21/Bluekeep-HunterCVE-2019-0708, A tool which mass hunts for bluekeep vulnerability for exploitation.★ 4Ravaan212022-09-17CandidatePoC-in-GitHub · davidfortytwo/bluekeepChecker and exploit for Bluekeep CVE-2019-0708 vulnerability★ 0davidfortytwo2023-03-02CandidatePoC-in-GitHub · tranqtruong/Detect-BlueKeepa simple tool to detect the exploitation of BlueKeep vulnerability (CVE-2019-0708)★ 1tranqtruong2023-03-25CandidatePoC-in-GitHub · rasan2001/Microsoft-Remote-Desktop-Services-Remote-Code-Execution-Vulnerability-CVE-2019-0708★ 0rasan20012024-05-10CandidatePoC-in-GitHub · adyanamul/Remote-Code-Execution-RCE-Exploit-BlueKeep-CVE-2019-0708-PoC★ 1adyanamul2024-06-02CandidatePoC-in-GitHub · denuwanjayasekara/CVE-Exploitation-ReportsCVE Exploitation Reports: CVE-2007-3280, CVE-2017-0144, CVE-2019-0708★ 0denuwanjayasekara2024-09-11CandidatePoC-in-GitHub · hualy13/CVE-2019-0708-Check★ 0hualy132024-10-31CandidatePoC-in-GitHub · isabelacostaz/CVE-2019-0708-POC★ 0isabelacostaz2025-04-30CandidatePoC-in-GitHub · GopeshKachhadiya/Windows-2A hands-on Windows 7 lab designed to demonstrate the real-world impact of the BlueKeep (CVE-2019-0708) vulnerability through practical exploitation and security analysis.★ 0GopeshKachhadiya2026-01-05CandidatePoC-in-GitHub · emmadej1234/bluekeep-metasploit-lab-projectExploiting BlueKeep (CVE-2019-0708) on Windows 7 using Metasploit★ 0emmadej12342026-04-17CandidatePoC-in-GitHub · Ayomide-29/bluekeep_metasploit_practiceExploiting bluekeep (CVE-2019-0708) on windows 7 using metasplotable★ 0Ayomide-292026-04-17CandidatePoC-in-GitHub · Nweks/Bluekeep-Metasploit-Lab-ProjectExploiting Bluekeep (CVE-2019-0708) on windows 7 using metasploit (Esucational lab)★ 0Nweks2026-04-19CandidatePoC-in-GitHub · Mohaimenul370/Perform-an-RDP-exploitation-using-the-BlueKeep-vulnerability-CVE-2019-0708-on-Windows★ 0Mohaimenul3702026-08-14CandidatePoC-in-GitHub · SebasPV27/Explotacion-RCE-Pentesting-BlueKeep-CVE-2019-0708-Demostración práctica y bitácora técnica de explotación de BlueKeep (CVE-2019-0708) en RDP usando Nmap y Metasploit, documentando la resolución de errores en el entorno virtual.★ 0SebasPV272026-08-24Candidate