NOOB2ROOT

CVE watch CVE-2019-0708 Known exploited

BlueKeep: pre-auth RCE in RDP

A use-after-free in Remote Desktop Services allowed unauthenticated, wormable remote code execution against a huge installed base of Windows hosts.

Severity
9.8
critical
Vendor
Microsoft
Disclosed
14 May 2019
Affected
Windows RDP (RDS)

CVSS breakdown

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Analysis

Placeholder analysis — replace before publishing.

References