Nearly a million devices are vulnerable to attacks involving a Windows called BlueKeep, and it appears that hackers have already begun scanning the web in search of potential targets.
The vulnerability, identified as CVE-2019-0708, affects Windows Remote Desktop Services (RDS) and was resolved by Microsoft with the May 2019 Patch Tuesday updates. The flaw has been described as a worm and can be used by malware to spread just like the infamous WannaCry ransomware that plagued us in 2017 via the EternalBlue exploit.

An attacker without access rights could use the flaw to execute arbitrary code and take control of a system without user interaction by sending specially crafted requests over the Remote Desktop Protocol (RDP).
Microsoft has released patches for Windows 7, Server 2008, XP, and Server 2003.users Windows 7 can prevent the attacks by enabling Network Level Authentication (NLA) or blocking TCP port 3389.
Many expect to see attacks involving BlueKeep at any time, as several proof-of-concept (PoC) exploits have already been developed – although none of the PoC exploits have been made public. Industrial and medical products are also at risk.
Robert Graham of Errata Security conducted an internet scan and found over 923,000 devices that appear to be vulnerable to BlueKeep attacks.
"Hackers are likely to launch their attacks in the next month or two and wreak havoc with these machines," Graham said.
The expert has also identified over 1.4 million systems that appear to have received the appropriate patches and about 1.2 million that cannot be exploited due to the use of NLA or the Credential Security Provider Support Protocol (CredSSP).
At least two organizations in cyberspace have already reported seeing scanning activity targeting the CVE-2019-0708 exploit.
GreyNoise Intelligence reports that all activity was traced to Tor exit nodes and believes it is likely to have been carried out by a single hacker.
Greece, together with the Netherlands, Russia, China, the United States, Germany, Vietnam, North Korea and Canada are the main countries with the highest risk for this exploit!
Install the patches released by Microsoft for CVE-2019-0708 IMMEDIATELY.
