-
BlueKeep exploitation expected soon
Several hours ago, there was a lot of noise on Twitter about a Github explanation on how to “weaponize” BlueKeep, triggering fears it could soon be widely expolited.
BlueKeep Warning: someone published a slide deck explaining how to turn the crash PoC into RCE. I expect we'll likely see widespread exploitation soon.https://t.co/MG2IZfy5B5
— MalwareTech (@MalwareTechBlog) July 22, 2019
Dan Goodin‘s article on ArsTechnica.com is fairly succinct:
BEWARE OF WORMABLE EXPLOITS —
Chances of destructive BlueKeep exploit rise with new explainer posted online
We’ll be keeping an eye on Kevin Beaumont’s Twitter feed, to see what he posts about it today.Are you protected?
UPDATE:
Kevin Beaumont is also warning about a more imminent threat from BlueKeepI've updated this thread with @0xeb_bp's #BlueKeep exploitation technical document, newly released today – it shows how to reach UAF. The bar for (unreliable) public exploitation POC is lowering significantly. https://t.co/UX1ujWaQik
— Kevin Beaumont (@GossiTheDog) 23 July 2019