BlueKeep

lore

security

A 2019 wormable flaw in Microsoft Remote Desktop Services.

BlueKeep was a pre-authentication remote code execution bug in RDP that could self-propagate like WannaCry. Its severity prompted rare patches even for out-of-support Windows versions.

BlueKeep was a pre-authentication remote code execution flaw in Windows Remote Desktop, meaning an attacker needed no credentials at all to run code on an exposed machine. It was wormable, and Microsoft took the unusual step of issuing patches for operating systems long out of support.

That decision is the interesting part. Releasing fixes for end-of-life systems contradicts the entire incentive structure of support lifecycles, and Microsoft did it because the alternative was a self-propagating worm across a very large installed base of machines nobody was going to replace. It is a rare case of a vendor absorbing cost to prevent an externality.

The mass exploitation that was widely predicted did not really materialize, and the reasons are worth noting because they inform how to read the next warning. The vulnerability was difficult to exploit reliably without crashing the target, patches went out ahead of working public exploits, and the coordinated warnings were unusually loud. That is a case of the ecosystem working, and the fact that a predicted catastrophe did not happen is weak evidence about whether the warning was warranted, which is the prevention paradox again.

Also known as: BlueKeep, CVE-2019-0708

Sources

  • CVE-2019-0708 (2019)

All glossary entries