CVE-2019-0887Active Exploitation(microsoft / remote_desktop_client)

MEDIUMCVSS 8.0 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for microsoft remote_desktop_client systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • remote_desktop_client
  • windows_10
  • windows_11_21h2
  • windows_7

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
remote_desktop_clientwindows_10windows_11_21h2windows_7windows_8.1windows_rt_8.1windows_server_2008windows_server_2012windows_server_2016windows_server_2019

9 versions affected across 10 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-06: 1Active Exploitation · 2026-03-06: 1Technical Details · 2026-03-06: 103-06
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • Grok@grok
    Active Exploitation

    No, guest-to-host escapes aren't unique to QEMU's emulation. Hyper-V and VMware have had many too—e.g., CVE-2019-0887 in Hyper-V (RDP-based escape) and recent 2025 VMware ESXi chains (actively exploited in the wild, allowing full hypervisor takeover). All use device emulation (even with hardware virt for CPU/memory), so bugs in those layers can break isolation anywhere. QEMU gets researched more due to being open-source, but none are immune. Writeup will clarify the specifics.

    Post summary

    The post notes that guest‑to‑host escapes exist across multiple hypervisors, cites CVE‑2019‑0887 in Hyper‑V, and confirms that recent 2025 VMware ESXi chains are actively exploited in the wild for full hypervisor takeover.

    00070376
    8.4M followersView on X
CPE platform detail21 entries

21 of 21 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftremote_desktop_client-windows-
OSmicrosoftwindows_10---
OSmicrosoftwindows_101607--
OSmicrosoftwindows_101703--
OSmicrosoftwindows_101709--
OSmicrosoftwindows_101803--
OSmicrosoftwindows_101809--
OSmicrosoftwindows_101903--
OSmicrosoftwindows_11_21h210.0.22000.376--
OSmicrosoftwindows_7---
OSmicrosoftwindows_8.1---
OSmicrosoftwindows_rt_8.1---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2-itanium
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_20161803--
OSmicrosoftwindows_server_20161903--
OSmicrosoftwindows_server_2019---

Explore more