Internet scan found nearly one million systems vulnerable to BlueKeep
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-0708 | Unauthenticated RCE in Microsoft Remote Desktop Services (BlueKeep) CVE-2019-0708 is a use-after-free (CWE-416) vulnerability in Microsoft Remote Desktop Services, formerly Terminal Services, in which an unauthenticated attacker can connect to a target system over RDP and send specially crafted requests to trigger the flaw. Because the trigger requires no authentication, the flaw is wormable: a successful exploit grants remote code execution on the target host, potentially with elevated privileges, and could allow self-propagating attacks similar to WannaCry. Organizations running the affected Microsoft Remote Desktop Services, particularly legacy Windows releases still accepting inbound RDP connections, are in scope. Exploitation is confirmed in the wild: the flaw (nicknamed BlueKeep) is listed in CISA's KEV catalog (added 2021-11-03), CISA notes known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days. Do: Apply Microsoft's security updates for CVE-2019-0708 per vendor instructions, prioritizing legacy or end-of-support Windows systems exposed to inbound RDP. As mitigation, restrict RDP (TCP 3389) to trusted networks or VPN access, require Network Level Authentication (NLA), and audit perimeter firewalls and public scans for open RDP listeners. The vulnerability is in the CISA KEV catalog, so patching is treated as a required action for federal and high-risk environments. | 9.8 | 100% | KEV ransomware PoC ×4 |
| masson the order of millions of internet-exposed RDP endpoints and far more internal systems |
Full article808 words · extracted from securityaffairs.com · click to collapse

Roughly one million devices are vulnerable to attacks exploiting the BlueKeep Windows vulnerability and hackers are ready to hit them.
Yesterday I reported the discovery made by experts at GreyNoise that detected scans for systems vulnerable to the BlueKeep (CVE-2019-0708) vulnerability.
The scans were first detected on May 25, 2019, experts explained that a single threat actor launched them from the Tor network to hide their identities.
GreyNoise is observing sweeping tests for systems vulnerable to the RDP "BlueKeep" (CVE-2019-0708) vulnerability from several dozen hosts around the Internet. This activity has been observed from exclusively Tor exit nodes and is likely being executed by a single actor. pic.twitter.com/iGwuGuD4Rq
— GreyNoise (@GreyNoiseIO) May 25, 2019
Bad Packets researchers also observed scanning activity associated with the BlueKeep, most of the requests originated from the Netherlands, Russia. and China.
BlueKeep (CVE-2019-0708) #RDP scans detected per country:
— Bad Packets by Okta (@bad_packets) May 27, 2019
🇳🇱 Netherlands 3,652
🇷🇺 Russia 2,376
🇨🇳 China 2,209
🇺🇸 United States 537
🇰🇷 South Korea 293
🇩🇪 Germany 179
🇻🇳 Vietnam 168
🇨🇦 Canada 63
🇬🇷 Greece 54
🇱🇻 Latvia 19
All Other Countries 36 pic.twitter.com/eBQ1OC1U93
The vulnerability, tracked as CVE-2019-0708, impacts the Windows Remote Desktop Services (RDS) and was addressed by Microsoft with May 2019 Patch Tuesday updates. BlueKeep is a wormable flaw that can be exploited by malware authors to create malicious code with WannaCry capabilities.
As explained by Microsoft, this vulnerability could be exploited by malware with wormable capabilities, it could be exploited without user interaction, making it possible for malware to spread in an uncontrolled way into the target networks.
Many security experts have already developed their own exploit code for this issue without publicly disclosing it for obvious reasons.
Microsoft has released patches for Windows 7, Server 2008, XP and Server 2003. Windows 7 and Server 2008 users can prevent unauthenticated attacks by enabling Network Level Authentication (NLA), and the threat can also be mitigated by blocking TCP port 3389.
Experts at the SANS Institute observed two partial exploits that are publicly available. Chaouki Bekrar, the founder of zero-day broker firm Zerodium, explained that the flaw can be exploited remotely by an unauthenticated user to gain access to a device with SYSTEM privileges. Researchers at McAfee developed a PoC exploit that could be exploited to get remote code execution.
Other experts also announced to have successfully developed exploits for BlueKeep, including Kaspersky, Check Point, and MalwareTech.
Now the popular expert Robert Graham has scanned the Internet for vulnerable systems. He discovered more than 923,000 potentially vulnerable devices using the masscan port scanner and a modified version of rdpscan,
The initial scan executed with masscan lasted a couple of hours and allowed the expert to find all the devices running Remote Desktop, roughly 7,629,102 results.
“However, there is a lot of junk out there that’ll respond on this port. Only about half are actually Remote Desktop.” explained Graham.
“Masscan only finds the open ports, but is not complex enough to check for the vulnerability. Remote Desktop is a complicated protocol. A project was posted that could connect to an address and test it, to see if it was patched or vulnerable. I took that project and optimized it a bit, rdpscan, then used it to scan the results from masscan. It’s a thousand times slower, but it’s only scanning the results from masscan instead of the entire Internet.”
The scan revealed 923,671 potentially vulnerable systems, likely hackers will launch a massive offensive in the next weeks.
“The upshot is that these tests confirm that roughly 950,000 machines are on the public Internet that are vulnerable to this bug. Hackers are likely to figure out a robust exploit in the next month or two and cause havoc with these machines. ” Graham added.
Below the detailed results of the scans conducted by the expert:
- 1447579 UNKNOWN – receive timeout
- 1414793 SAFE – Target appears patched
- 1294719 UNKNOWN – connection reset by peer
- 1235448 SAFE – CredSSP/NLA required
- 923671 VULNERABLE — got appid
- 651545 UNKNOWN – FIN received
- 438480 UNKNOWN – connect timeout
- 105721 UNKNOWN – connect failed 9
- 82836 SAFE – not RDP but HTTP
- 24833 UNKNOWN – connection reset on connect
- 3098 UNKNOWN – network error
- 2576 UNKNOWN – connection terminated
Summarizing, over 1.4 million machines have been patched and 1.2 million devices refused any unauthenticated connection.
Let’s close confirming the availability of the micropatch for the BlueKeep vulnerability that was released by experts at 0patch that can be deployed by administrators to protect always-on servers.
Thank you
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – BlueKeep, hacking)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/86240/hacking/internet-scan-bluekeep.html