{"cveID":"CVE-2019-0708","vendorProject":"Microsoft","product":"Remote Desktop Services","vulnerabilityName":"Microsoft Remote Desktop Services Remote Code Execution Vulnerability","dateAdded":"2021-11-03","shortDescription":"Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-05-03","knownRansomwareCampaignUse":"Known","notes":"https://nvd.nist.gov/vuln/detail/CVE-2019-0708","cwes":["CWE-416"],"year":2019,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2019-0708","technique":"T1133","technique_name_at_mapping":"External Remote Services","mapping_type":"exploitation_technique","capability_group":"code_execution","comments":"CVE-2019-0708, also known as BlueKeep, is a remote code execution vulnerability present in the Windows Remote Desktop Services. Blue Keep can enable remote unauthenticated attackers to run arbitrary code, or conduct denial of service attacks, as well as potentially take control of vulnerable systems.","references":["https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a","https://www.bleepingcomputer.com/news/security/bluekeep-scanner-discovered-in-watchbog-cryptomining-malware/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2019-0708","technique":"T1059.004","technique_name_at_mapping":"Unix Shell","mapping_type":"primary_impact","capability_group":"code_execution","comments":"CVE-2019-0708, also known as BlueKeep, is a remote code execution vulnerability present in the Windows Remote Desktop Services. Blue Keep can enable remote unauthenticated attackers to run arbitrary code, or conduct denial of service attacks, as well as potentially take control of vulnerable systems.","references":["https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a","https://www.bleepingcomputer.com/news/security/bluekeep-scanner-discovered-in-watchbog-cryptomining-malware/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2019-0708","technique":"T1498","technique_name_at_mapping":"Network Denial of Service","mapping_type":"secondary_impact","capability_group":"code_execution","comments":"CVE-2019-0708, also known as BlueKeep, is a remote code execution vulnerability present in the Windows Remote Desktop Services. Blue Keep can enable remote unauthenticated attackers to run arbitrary code, or conduct denial of service attacks, as well as potentially take control of vulnerable systems.","references":["https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a","https://www.bleepingcomputer.com/news/security/bluekeep-scanner-discovered-in-watchbog-cryptomining-malware/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1059.004","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Unix Shell","name_at_mapping":"Unix Shell","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":18,"has_detection_strategy":true},{"id":"T1133","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"External Remote Services","name_at_mapping":"External Remote Services","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":20,"has_detection_strategy":true},{"id":"T1498","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Network Denial of Service","name_at_mapping":"Network Denial of Service","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":3,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":["8400629e-79a9-4737-b387-5db940ab2367","aaa5b30d-f418-420b-83a0-299cb6024885"],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}