CVE-2019-0887 is a Microsoft Remote Desktop Services remote code execution vulnerability associated with abuse of clipboard redirection by an authenticated attacker. The available context ties the issue to Check Point Research’s Reverse RDP findings and Microsoft’s subsequent assignment of CVE-2019-0887 for new implications affecting Microsoft Hyper-V. In this attack model, a malicious or attacker-controlled RDP server abuses the clipboard redirection channel exposed to a connecting client. The supporting material indicates the clipboard channel permits server influence over client clipboard content and file-transfer semantics, creating a path to code execution on the client side when clipboard data is processed or pasted. Specific Microsoft-internal vulnerable functions are not identified in the provided content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Visual Studio C++ project implementing a proof-of-concept (POC) exploit for CVE-2019-0887, a Remote Desktop Protocol (RDP) Remote Code Execution Vulnerability affecting Microsoft Windows. The main code is in 'CVE-2019-0887/dllmain.cpp', which builds a DLL that hooks several Windows API functions (GetClipboardData, CreateFileW, GetFileAttributesW, DragQueryFileW) using the Microsoft Detours library. The exploit manipulates clipboard and file operations to surreptitiously drop a copy of 'cmd.exe' into the user's Startup folder ('AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup/cmd.exe'), achieving persistence and code execution on next login. The project includes standard Visual Studio solution and project files, precompiled header files, and a NuGet package reference for Detours. No network endpoints are present; the attack vector is local, requiring code execution on the target system (e.g., via DLL injection or similar means). The exploit demonstrates the vulnerability's impact by showing how clipboard/file operations can be hijacked to achieve arbitrary file writes and persistence.
This repository provides an operational exploit for CVE-2019-0887, a vulnerability in Microsoft Windows RDP clipboard sharing (rdpclip.exe). The exploit consists of two main components: a malicious DLL (winhlp.dll) and an injector executable (hook.exe). The DLL is designed to be injected into the rdpclip.exe process, where it hooks several Windows API functions related to clipboard and file operations (GetClipboardData, CreateFileW, GetFileAttributesW, DragQueryFileW) using the Detours library. The hooks manipulate clipboard/file operations to drop a payload (winhlp64.exe) into the Startup folder, ensuring code execution on user logon. The injector (hook.exe) locates the rdpclip.exe process and injects the DLL using CreateRemoteThread and LoadLibraryA. The README provides instructions for compilation, deployment, and triggering the exploit (e.g., via a scheduled task on user session connection). The exploit requires local access to the target system to place the necessary files and set up the trigger. The main attack vector is local privilege escalation or persistence via manipulation of RDP clipboard operations. The code is written in C++ and uses the Microsoft Detours library for API hooking.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability in Remote Desktop Services.
A Microsoft-assigned CVE tied to new implications of the “Reverse RDP Attack” affecting Hyper-V, where an RDP server can attack the connecting client/host environment.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.