Input validation error in Microsoft Windows and Windows Server - CVE-2019-0708
Published: May 15, 2019 / Updated: March 25, 2023
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of user-supplied input when processing RDP packets in Windows Remote Desktop Services. A remote unauthenticated attacker can send a series of specially crafted requests and execute arbitrary code on the target system.
Successful exploitation of vulnerability may allow an attacker to compromise vulnerable system.
Note, this vulnerability is known as BlueKeep.
In-the-wild exploitation of the vulnerability was detected on November 2, 2019.
Affected software
Windows Server
How to mitigate CVE-2019-0708
Links to Public Exploits and PoC-codes
- Exploit #8937 - Detect-BlueKeep (a simple tool to detect the exploitation of BlueKeep vulnerability (CVE-2019-0708)) (March 25, 2023)
- Exploit #6653 - Nephael-CVE-2019-0708-Exploit (MS CVE 2019-0708 Python Exploit) (August 23, 2021)
- Exploit #6124 - Microsoft Windows Remote Desktop - 'BlueKeep' Denial of Service (Metasploit) (June 17, 2021)
- Exploit #5995 - Microsoft Windows - BlueKeep RDP Remote Windows Kernel Use After Free (Metasploit) (June 17, 2021)
- Exploit #5102 - Mass-scanner-for-CVE-2019-0708-RDP-RCE-Exploit (Scan through given ip list) (January 31, 2021)
- Exploit #4821 - CVE-2019-0708-PoC (CVE-2019-0708-PoC It is a semi-functional exploit capable of remotely accessing a Windows computer by exploiting the aforementioned vulnerability, this repository also contains notes on how to complete the attack.) (November 10, 2020)
- Exploit #4787 - CVE-2019-0708-EXP-MSF- (CVE-2019-0708-EXP(MSF) Vulnerability exploit program for cve-2019-0708) (November 3, 2020)
- Exploit #2605 - Wincrash (Mass exploit for CVE-2019-0708) (April 27, 2020)
- Exploit #2362 - CVE-2019-0708-Poc-exploit (CVE-2019-0708 EXPloit-poc 漏洞描述 微软官方紧急发布安全补丁,修复了一个Windows远程桌面服务的远程代码执行漏洞CVE-2019-0708,该漏洞影响了某些旧版本的Windows系统。此漏洞是预身份验证,无需用户交互。当未经身份验证的攻击者使用RDP(常见端口3389)连接到目标系统并发送特制请求时,可以在目标系统上执行任意命令。甚至传播恶意蠕虫,感染内网其他机器。类似于2017年爆发的WannaCry等恶意勒索软件病毒 (April 7, 2020)
- Exploit #2025 - CVE-2019-0708-EXPloit-3389 (EXPloit-poc: https://pan.baidu.com/s/184gN1tJVIOYqOjaezM_VsA 提取码:e2k8) (March 18, 2020)
- Exploit #2024 - CVE-2019-0708 (Proof of concept exploit for CVE-2019-0708) (March 18, 2020)
- Exploit #2026 - CVE-2019-0708-poc (proof of concept exploit for Microsoft Windows 7 and Server 2008 RDP vulnerability) (March 18, 2020)
- Exploit #2035 - Wincrash (Mass exploit for CVE-2019-0708) (March 18, 2020)
- Exploit #2039 - ispy (ispy V1.0 - Eternalblue(ms17-010)/Bluekeep(CVE-2019-0708) Scanner and exploit ( Metasploit automation )) (March 18, 2020)
- Exploit #2080 - XploitHunt (XploitHunt is tool which help pentester to get exploit details by providing CVE-IDs) (March 18, 2020)
- Exploit #2102 - CVE-2019-0708-PoC (Windows RPD Exploit) (March 18, 2020)
- Exploit #2103 - CVE-2019-0708-EXPloit (POCexp:https://pan.baidu.com/s/184gN1tJVIOYqOjaezM_VsA 提取码:e2k8 ) (March 18, 2020)
- Exploit #2104 - Input validation error (March 18, 2020)
- Exploit #2105 - CVE-2019-0708 (A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerabilit (March 18, 2020)
- Exploit #2106 - CVE-2019-0708 (A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerabilit (March 18, 2020)
- Exploit #2160 - CVE-2019-0708 (CVE-2019-0708 Exploit) (March 18, 2020)
- Exploit #2173 - Remote-Desktop-Services-Remote-Code-Execution-Vulnerability-CVE-2019-0708- (rce exploit , made to work with pocsuite3) (March 18, 2020)
- Exploit #2192 - CVE-2020-0601 (A Windows Crypto Exploit) (March 18, 2020)
- Exploit #2201 - cve_searchsploit (Search an exploit in the local exploitdb database by its CVE) (March 18, 2020)
- Exploit #2023 - RDS_CVE-2019-0708 (exploit CVE-2019-0708 RDS) (March 18, 2020)
- Exploit #2022 - CVE-2019-0708-Exploit (Using CVE-2019-0708 to Locally Promote Privileges in Windows 10 System) (March 18, 2020)
- Exploit #2021 - CVE-2019-0708-exploit (CVE-2019-0708-exploit) (March 18, 2020)
- Exploit #2020 - CVE-2019-0708 (A Win7 RDP exploit) (March 18, 2020)
- Exploit #239 - CVE-2019-0708 (PoC exploit for BlueKeep (CVE-2019-0708)) (March 18, 2020)
- Exploit #91 - CVE-2019-0708 BlueKeep Microsoft Remote Desktop RCE Check (March 18, 2020)
- Exploit #240 - CVE-2019-0708 (CVE-2019-0708 RDP Remote Code Execute Exploit ) (March 18, 2020)
- Exploit #241 - Mass-scanner-for-CVE-2019-0708-RDP-RCE-Exploit (Scan through given ip list) (March 18, 2020)
- Exploit #242 - CVE-2019-0708 (High level exploit) (March 18, 2020)
- Exploit #243 - CVE-2019-0709 (Exploit In Progress) (March 18, 2020)
- Exploit #244 - CVE-2019-0708-Tool (A social experiment) (March 18, 2020)
- Exploit #245 - CVE-2019-0709 (CVE-2019-0708 Exploit using Python) (March 18, 2020)
- Exploit #246 - CVE-2019-0708 (3389远程桌面代码执行漏洞CVE-2019-0708批量检测工具(Rdpscan Bluekeep Check)) (March 18, 2020)
- Exploit #247 - cve-2019-0708 (CVE-2019-0708 Exploit Tool) (March 18, 2020)
- Exploit #248 - bluekeep_CVE-2019-0708_poc_to_exploit (An Attempt to Port BlueKeep PoC from @Ekultek to actual exploits) (March 18, 2020)
- Exploit #249 - cve_2019_0708_bluekeep_rce (bluekeep exploit) (March 18, 2020)
- Exploit #250 - CVE-2019-0708 (CVE-2019-0708 With Metasploit-Framework Exploit) (March 18, 2020)
- Exploit #251 - msf-module-CVE-2019-0708 (Metasploit module for CVE-2019-0708 (BlueKeep) - https://github.com/rapid7/metasploit-framework/tree/5a0119b04309c8e61b44763ac08811cd3ecbbf8d/modules/exploits/windows/rdp) (March 18, 2020)
- Exploit #252 - CVE-2019-0708-EXP-MSF- (CVE-2019-0708-EXP(MSF) Vulnerability exploit program for cve-2019-0708) (March 18, 2020)
- Exploit #253 - bluekeep (CVE- 2019-0708 مرحبا هذه هي ثغرة الارديبي الاخيرة رقمها ) (March 18, 2020)
- Exploit #254 - CVE-2019-0708 (initial exploit for CVE-2019-0708, BlueKeep CVE-2019-0708 BlueKeep RDP Remote Windows Kernel Use After Free The RDP termdd.sys driver improperly handles binds to internal-only channel MS_T120, allowing a malformed Disconnect Provider Indic (March 18, 2020)
- Exploit #255 - bluekeep-exploit (Bluekeep(CVE 2019-0708) exploit released) (March 18, 2020)
- Exploit #1517 - CVE-2019-0708 BlueKeep RDP Remote Windows Kernel Use After Free (March 18, 2020)