HomeSecurityBlueKeep one million vulnerable Windows computers

BlueKeep one million vulnerable Windows computers

Nearly a million Windows computers are vulnerable to BlueKeep, a security flaw in the Remote Desktop Protocol (RDP) service that affects older versions of the Windows operating system.

This number comes to limit the initial fears that over seven million devices were at risk, although the risk still exists, as a million devices is no joke.

BlueKeep

The BlueKeep vulnerability, which has been given the designation CVE-2019-0708, has been a concern for the IT and cybersecurity communities for the past two weeks.

The issue was first reported on the May 2019 Patch Tuesday earlier this month.

Microsoft then released security updates but warned that the BlueKeep flaw was a worm, meaning hackers and malware could potentially exploit the vulnerability to double the number of victims since the worm essentially spreads itself.

As happened with EnternalBlue SMB during WannaCry, NotPetya in 2017.

However, despite the vulnerability's level of risk, no attacks have been observed, mainly because there is no public PoC that can be adapted to launch attacks.

Some scans have been observed, but it's not clear who's behind them, according to security firm GreyNoise, which observed the activity over the weekend.

The good news is that companies can apply patches immediately to mitigate this risk. The updates are rolling out now and are available for Windows XP (!), 7, Server 2003, and Server 2008, all versions of Windows that are vulnerable to BlueKeep attacks.

BlueKeep windows

In research published today, Robert Graham, head of security research firm Errata Security and developer of the Internet scanning utility Masscan, revealed precise statistics on the number of Windows systems that are still vulnerable to BlueKeep attacks.

While it was initially believed that there were nearly 7.6 million Windows systems connected to the Internet that were vulnerable to attacks, Graham said today that the number is actually around 950,000.

Most of the seven million systems that have port 3389 (RDP exposed to the Internet) are not actually Windows systems or do not have an RDP service on that port, Graham discovered.

The researcher said that the majority of Windows systems with an RDP service exposed directly to the Internet are safe, as there are around 1.5 million such devices that respond to scans in a specific way.

Hackers are likely to launch intense attacks next month and wreak havoc on these machines

Additionally, due to the limitations of his scans, Graham was unable to test Windows systems on internal networks, which are likely hiding more vulnerable computers.
The tool Graham used during his research is available on GitHub under the name rdpscan. It is a mix of his own masscan tool and a scanner for BlueKeep developed by RiskSense.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS