Which 2019 Windows vulnerability was nicknamed BlueKeep?
Answer
CVE-2019-0708
Answer
CVE-2019-0708
The 2019 Windows vulnerability nicknamed BlueKeep was CVE-2019-0708.
BlueKeep was a remote-code-execution vulnerability in Microsoft's Remote Desktop Services. It affected several older Windows versions, including Windows 7 and Windows Server 2008. A remote attacker could potentially exploit a vulnerable machine before authentication, making the flaw particularly concerning for systems exposed to the internet.
Microsoft disclosed and patched BlueKeep in May 2019. Although researchers warned that it could support worm-like propagation, widespread exploitation on the scale of WannaCry did not occur. Microsoft even issued patches for some unsupported Windows editions, an unusual step reflecting the perceived risk.
BlueKeep is often confused with EternalBlue because both involved Microsoft networking technology and prompted warnings about self-spreading attacks. They were different vulnerabilities: BlueKeep affected Remote Desktop Services, whereas EternalBlue targeted SMBv1. The CVE number provides the unambiguous way to distinguish them.
Source: Wikipedia · fact-checked Sept. 2026