Remote Desktop Services (RDP) Remote Code Execution Vulnerability - Update
CVE: 2019-0708Last updated: 24/05/19
Last week Microsoft announced a vulnerability that affects Microsoft RDP (CVE-2019-0708 – now known as BlueKeep). Since our initial website advisory on this last week, our researchers have been monitoring the developments of this vulnerability.
We'd like to advise our customers of the need to address any exposure to this vulnerability as a matter of urgency.
The two key contributing factors for this high risk vulnerability are:
Since being disclosed as part of Microsoft’s Patch Tuesday release, multiple security researchers have developed and released working code exploiting this vulnerability. Although initially the exploit code only created a “Blue Screen of Death” denial of service event, new exploit code (see example created by McAfee’s security research team) has demonstrated the real threat of remote code execution. With the potential public availability of this code the likelihood of attempted exploits has risen.
Additionally, raising the risk further, a number of scanners have been released which enables users to identify vulnerable systems – both within their own environment and across the internet. In line with this, our SOC team have observed a significant increase in activity on TCP port 3389 – an indication of potential scanning, either by security researchers or threat actors.
Our recommendations
 Integrity360 recommends clients implement the required updates released as part of Microsoft's May patch Tuesday to exposed systems. The update addresses the vulnerability by correcting how Remote Desktop Services handles connection requests.
Additionally, Microsoft recommends the following two mitigation actions:
If you need further information or assistance in mitigating this threat please contact your Integrity360 account manager or email info@integrity360.com.
As always, Integrity360 managed service customers will be covered through our proactive security approach.