HomeSecurityMicrosoft issues second warning regarding BlueKeep

Microsoft issues second warning about BlueKeep

Microsoft has previously warned companies to patch older versions of Windows due to a serious vulnerability in the Remote Desktop Protocol (RDP) service, which has been likened to the EternalBlue exploit that powered WannaCry, NotPetya, and Bad Rabbit ransomware. But things got worse, with limited “proof-of-concept” code to exploit the vulnerability (known as BlueKeep or CVE-2019-0708) appearing online in the past two days.

BlueKeep

“Microsoft is confident that an exploit exists for this vulnerability, and if recent reports are accurate, nearly a million computers connected directly to the internet are still vulnerable to CVE-2019-0708,” said Simon Pope, Incident Response Manager for the Microsoft Troubleshooting Center (MSRC).

It appears that scans of computers vulnerable to BlueKeep have been happening continuously for a week at an ever-increasing rate. The operating system maker is now sounding the final alarm before the real attacks begin.

Patches are currently available for Windows XP, Windows Vista, Windows 7, Windows Server 2003, and Windows Server 2008 – the versions of Windows that are vulnerable to BlueKeep attacks.

Microsoft issues second warning

Microsoft warned about the vulnerability on May 14, this month's regular Patch Tuesday. At the time, it said the flaw was dangerous because it not only allowed remote execution, but the bug was also a "computer worm" (a self-replicating and malicious computer program).

"We recommend that you update all affected systems as soon as possible," Simon Pope said.

Simon Pope also warns companies that the impression they have that if work offices are not connected to the Internet, they are safe is not true.

“It only takes one vulnerable computer connected to the internet to offer a potential gateway into […] corporate networks, where advanced malware could spread, infecting computers across the enterprise,” he said.

Pope also warns companies against the mistaken assumption that they are safe just because no attacks have been observed so far.

"It's only been two weeks since the patch was released and there has been no sign of a computer worm. That doesn't mean we've been safe, of course," he said.

He likened the relative calm to the two months following the publication of the EternalBlue exploit and the WannaCry outbreak, which also had limited attacks at first.

These rare attacks later spread and EternalBlue became one of the most popular exploits on the market as more demo code became available and hacker groups began to learn how to fully utilize the exploit.

The working demo code is available on GitHub

For now, the BlueKeep code published on GitHub is not as dangerous as people think, as it can only crash a remote vulnerable system, but not execute code on it.

Microsoft issues second warning about BlueKeep

Microsoft issues second warning about BlueKeep

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS