Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: May 3, 2022

CVE-2019-0708

High
EPSS 94.5%CISA KEVRansomware
Microsoft/Remote Desktop Services

Description

Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.

EPSS — Exploit Probability

94.5%

Higher than 100.0% of all CVEs

Required Action

https://nvd.nist.gov/vuln/detail/CVE-2019-0708

Risk Assessment

CRITICAL
In CISA KEV
High EPSS
Ransomware

Details

Severity
High
EPSS
94.5%
CISA KEV
Yes
Ransomware
Known
Articles
0

Timeline

Published

Nov 3, 2021

Added to KEV

Nov 3, 2021

Remediation Due

May 3, 2022

Affected Product

Microsoft

Remote Desktop Services

View all Microsoft CVEs