Register Free Newsletter Plus Membership
  • Home
    • Newsletters/Alerts
    • Forums
    • About
    • MS-DEFCON System
    • Master Patch List
    • Register
    • Login
Microsoft Patch Defense Condition level 2 Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it.
SIGN IN Not a member? REGISTER PLUS MEMBERSHIP
  • Kevin Beaumont: Still no sign of BlueKeep in the wild

    Home » Forums » Newsletter and Homepage topics » Kevin Beaumont: Still no sign of BlueKeep in the wild

    • This topic has 7 replies, 6 voices, and was last updated 5 years, 11 months ago by anonymous.

    Tags: BlueKeep

    Author
    Topic
    New Reply
    woody
    Manager
    July 18, 2019 at 3:24 am #1876364

    In case you were wondering, Kevin Beaumont hasn’t yet detected any BlueKeep infections: https://twitter.com/GossiTheDog/status/1151510296302931969 Goo
    [See the full post at: Kevin Beaumont: Still no sign of BlueKeep in the wild]

    2 users thanked author for this post.
    SueW, Elly
    Reply | Quote
    Viewing 2 reply threads
    Author
    Replies
    • Geo
      AskWoody Plus
      July 18, 2019 at 11:40 am #1876534
      woody wrote:

      In case you were wondering, Kevin Beaumont hasn’t yet detected any BlueKeep infections:

      Why Microsoft’s BlueKeep Bug Hasn’t Wreaked Havoc—Yet | WIRED      Further information on BlueKeep.

      2 users thanked author for this post.
      woody, b
      Reply | Quote
    • Steve S
      AskWoody Lounger
      July 18, 2019 at 11:57 am #1876539

      I got a question and this might be the best place to put it.

       

      First BlueKeep is CVE 2019-0708

      https://en.wikipedia.org/wiki/BlueKeep

      https://www.bleepingcomputer.com/news/security/bluekeep-remote-desktop-exploits-are-coming-patch-now/

      https://answers.microsoft.com/en-us/windows/forum/all/how-install-bluekeep-patch-for-windows-7/e1582d6b-9669-408c-a58f-0f7c7c1be651

      I am now going to explain why that is important. Here is ms advisory

      https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708

      Using Windows 7 Sp1 32 bit as example. The Kb’s are 4499164 and 4499175.

      Starting with 4499175. https://support.microsoft.com/en-us/help/4499175/windows-7-update-kb4499175

      Note this line:

      “Provides protections against a new subclass of speculative execution side-channel vulnerabilities, known as Microarchitectural Data Sampling, for 64-Bit (x64) versions of Windows (CVE-2019-11091, CVE-2018-12126, CVE-2018-12127, CVE-2018-12130). Use the registry settings as described in the Windows Client and Windows Server articles. (These registry settings are enabled by default for Windows Client OS editions, but disabled by default for Windows Server OS editions).”

      First this is talking about 64 bit not 32bit. Second no mention of CVE 2019-0708 (BlueKeep)

      Same in 4499164: https://support.microsoft.com/en-us/help/4499164/windows-7-update-kb4499164

      Also let check security only for 64 bit. which are the same exact KB’s

      One more part

      the page has this:  “For more information about the resolved security vulnerabilities, please refer to the Security Update Guide.” Lets do that:

      https://portal.msrc.microsoft.com/en-us/security-guidance

      Searching that page again has no mention of CVE 2019-0708. I checked the listed under

      March https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/ac45e477-1019-e911-a98b-000d3a33a34d

      April https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/18306ed5-1019-e911-a98b-000d3a33a34d

      May https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/e5989c8b-7046-e911-a98e-000d3a33a34d

      June https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/253dc509-9a5b-e911-a98e-000d3a33c573

      and July https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/48293f19-d662-e911-a98e-000d3a33c573

      If this was really patched, why no mention above in either the Security Update Release notes or KB pages?

      Reply | Quote
      • woody
        Manager
        July 18, 2019 at 12:54 pm #1876566

        Good question… and I don’t know the answer.

        Perhaps someone else here knows more of the details?

        Reply | Quote
      • Alex5723
        AskWoody Plus
        July 18, 2019 at 1:18 pm #1876582
        Steve S wrote:

        If this was really patched, why no mention above in either the Security Update Release notes or KB pages?

        It is mentioned here with list of updates including Win7 32bit kb4499164 & kb4499175

        CVE-2019-0708 | Remote Desktop Services Remote Code Execution Vulnerability
        Security Vulnerability
        Published: 05/14/2019
        MITRE CVE-2019-0708

        A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

        To exploit this vulnerability, an attacker would need to send a specially crafted request to the target systems Remote Desktop Service via RDP.

        The update addresses the vulnerability by correcting how Remote Desktop Services handles connection requests

        https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708

        Reply | Quote
        • Steve S
          AskWoody Lounger
          July 18, 2019 at 2:25 pm #1876595

          You might be missing the question. BlueKeep is a big Deal. Yes I agree you can find it there, but the KB pages you think would also mention it and the Security Updates notes, it definitely should be there. Yes I see this

          “The following CVEs have FAQs with additional information and may include * further steps to take after installing the updates. Please note that this is not a complete list of CVEs for this release.”.

          But again notice what the security update notes are suppose to be

          “For more information about the resolved security vulnerabilities, please refer to the Security Update Guide.”

          as big a deal at BlueKeep is IT Should be in the Security update guide. Please find it there.

          (as in notes of security patches, not general like you did.)

          Also the KB’s mention some CVE, but CVE 2019-0708 is not there.

          The point is why is such a Big deal not mentioned where it should be. If a users want to confirm that, yes this does patch BlueKeep, if it is not listed in the KB or the notes, how would they know for sure that, yes this is the right patch?

           

          • This reply was modified 5 years, 11 months ago by Steve S.
          • This reply was modified 5 years, 11 months ago by Steve S.
          Reply | Quote
      • Speccy
        AskWoody Lounger
        July 19, 2019 at 6:25 am #1876861

        Perhaps the answer you’re looking for lies within the Acknowledgments webpage: CVE-2019-0708 refers the UK’s National Cyber Security Centre (NCSC).

        • This reply was modified 5 years, 6 months ago by Speccy. Reason: Edited (irrelevant, off-topic info removed)
        Reply | Quote
    • anonymous
      Guest
      July 19, 2019 at 2:54 pm #1877000

      from 0 patch https://twitter.com/0patch

      Quote”So while we haven’t seen massive #BlueKeep attacks yet, this modified Metasploit module got published for DOSing a range of IP addresses with BlueKeep. It now only takes one troubled soul to launch this against the Internet. Please patch or @0patch if you haven’t yet!”

      And as NSA is also pushing you patch, maybe, just maybe the patch is a back door(?)

      https://www.nsa.gov/News-Features/News-Stories/Article-View/Article/1865726/nsa-cybersecurity-advisory-patch-remote-desktop-services-on-legacy-versions-of/

      3 users thanked author for this post.
      Speccy, columbia2011, woody
      Reply | Quote
    Viewing 2 reply threads
    Reply To: Kevin Beaumont: Still no sign of BlueKeep in the wild

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information:




     
    Cancel
DON'T MISS OUT!
Subscribe to the Free Newsletter
We promise not to spam you. Unsubscribe at any time.
Invalid email address
Thanks for subscribing!

Register
Lost your password?

Plus Membership

Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.

AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.


Get Plus!

Welcome to our unique respite from the madness.

It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.

Search Newsletters

Search Forums

Advanced Search

View the Forum

  • Recent Replies
  • My Replies
  • My Active Topics
  • New Posts in the Last day
  • Private Messages
  • Knowledge Base
  • How to use the Forums
  • All Forums
  • Search for Topics

    • Most popular topics
    • Topics with no replies
    • Recently active topics
    • New posts: Last day
    • New posts: Last three days
    • New posts: Last week
    • New posts: Last month
    • Topics with most replies
    • Latest topics

    Recent Topics

    • Windows 11 Insider Preview build 26200.5651 released to DEV by joep517
      3 hours, 16 minutes ago
    • Windows 11 Insider Preview build 26120.4441 (24H2) released to BETA by joep517
      3 hours, 17 minutes ago
    • iOS 26,, MacOS 26 : Create your own AI chatbot by Alex5723
      7 hours, 12 minutes ago
    • New PC transfer program recommendations? by DaveBoston
      1 hour, 33 minutes ago
    • Windows 11 Insider Preview Build 22631.5545 (23H2) released to Release Preview by joep517
      11 hours, 17 minutes ago
    • Windows 10 Build 19045.6029 (22H2) to Release Preview Channel by joep517
      11 hours, 18 minutes ago
    • Best tools for upgrading a Windows 10 to an 11 by Susan Bradley
      28 seconds ago
    • The end of Windows 10 is approaching, consider Linux and LibreOffice by Alex5723
      5 hours, 34 minutes ago
    • Extended Windows Built-in Disk Cleanup Utility by bbearren
      9 hours, 27 minutes ago
    • Win 11 24H2 June 2025 Update breaks WIFI by dportenlanger
      1 day, 6 hours ago
    • Update from WinPro 10 v. 1511 on T460p? by CatoRenasci
      4 hours, 11 minutes ago
    • System Restore and Updates Paused by veteran
      1 day, 8 hours ago
    • Windows 10/11 clock app by Kathy Stevens
      19 hours, 53 minutes ago
    • Turn off right-click draw by Charles Billow
      1 day, 12 hours ago
    • Introducing ChromeOS M137 to The Stable Channel by Alex5723
      1 day, 15 hours ago
    • Brian Wilson (The Beach Boys) R.I.P by Alex5723
      9 hours, 26 minutes ago
    • Master patch listing for June 10, 2025 by Susan Bradley
      1 day, 17 hours ago
    • Suggestions for New All in One Printer and a Photo Printer Windows 10 by Win7and10
      20 hours, 2 minutes ago
    • Purchasing New Printer. Uninstall old Printer Software First? by Win7and10
      1 day, 23 hours ago
    • KB5060842 Issue (Minor) by AC641
      11 hours, 16 minutes ago
    • EchoLeak : Zero Click M365 Copilot leak sensitive information by Alex5723
      2 days, 6 hours ago
    • 24H2 may not be offered June updates by Susan Bradley
      22 hours, 53 minutes ago
    • Acronis : Tracking Chaos RAT’s evolution (Windows, Linux) by Alex5723
      2 days, 18 hours ago
    • June 2025 updates are out by Susan Bradley
      17 minutes ago
    • Mozilla shutting Deep Fake Detector by Alex5723
      3 days, 9 hours ago
    • Windows-Maintenance-Tool (.bat) by Alex5723
      2 days, 18 hours ago
    • Windows 11 Insider Preview build 26200.5641 released to DEV by joep517
      3 days, 12 hours ago
    • Windows 11 Insider Preview build 26120.4250 (24H2) released to BETA by joep517
      3 days, 12 hours ago
    • Install Office 365 Outlook classic on new Win11 machine by WSrcull999
      3 days, 12 hours ago
    • win 10 to win 11 with cpu/mb replacement by aquatarkus
      3 days, 4 hours ago

    Recent blog posts

    • Best tools for upgrading a Windows 10 to an 11
    • Master patch listing for June 10, 2025
    • 24H2 may not be offered June updates
    • June 2025 updates are out
    • What goes on inside an LLM
    • The risk of remote access
    • The cruelest month for many Office users
    • Tracking protection and trade-offs in Edge

    My Profile

    Login and Registration

    • Log In
    • Register

    Key Links

    • > Computerworld's The Microsoft Patch Lady
    • > Computerworld's Woody on Windows
    • AskWoody Knowledge Base index
    • BlockaPatch tools
    • Gift subscription for Ask Woody Newsletter
    • Microsoft Answers Forum
    • Tasks for the Weekend YouTube Channel
    June 2025
    S M T W T F S
    1234567
    891011121314
    15161718192021
    22232425262728
    2930  
    « May    

    Remembering Woody

     

    Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.

    Mastodon profile for DefConPatch
    Mastodon profile for AskWoody

     

    Home • About • FAQ • Posts & Privacy • Forums • My Account
    Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts

    Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.

    Insert/edit link

    Enter the destination URL

    Or link to existing content

      No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.

        Notifications

        #