A year and a half after Microsoft disclosed the BlueKeep vulnerability affecting the Windows RDP service, more than 245,000 Windows systems remain unpatched and vulnerable to attack.

The number represents about 25% of the 950,000 systems initially discovered to be vulnerable to BlueKeep attacks during an initial scan in May 2019.
Similarly, more than 103,000 Windows systems also remain vulnerable to SMBGhost, a vulnerability in the Server Message Block v3 (SMB) protocol that ships with recent versions of Windows, which was disclosed in March 2020.
Both vulnerabilities allow attackers to take over Windows systems remotely and are considered some of the most serious bugs revealed in Windows in recent years.
However, despite their severity, many systems have remained unpatched, according to research compiled in recent weeks by SANS ISC operator Jan Kopriva.
Kopriva says that BlueKeep and SMBGhost are not the only vulnerabilities that hackers can exploit remotely and still have a strong presence online, exposing systems to attacks.
According to the Czech security researcher, there are still millions of systems accessible online that administrators have failed to patch and are vulnerable to remote takeovers. These include systems like IIS servers, Exim email clients, OpenSSL clients , and WordPress websites .
The reasons why these systems have remained unpatched remain unknown, but even recent warnings from US have not helped.
Two warnings were issued by the US National Security Agency (NSA), one issued in May (for the Exim bug CVE-2019-10149 exploited by Russian hackers) and a second in October (for the BlueKeep bug exploited by Chinese state hackers).
However, despite these warnings, there are still more than 268,000 Exim servers that have not been patched for the Exim bug and more than 245,000 for BlueKeep.
Kopriva says the numbers show that “even well-known vulnerabilities sometimes go unpatched for years.”.
