In case you were wondering, Kevin Beaumont hasn’t yet detected any BlueKeep infections: https://twitter.com/GossiTheDog/status/1151510296302931969 Goo
[See the full post at: Kevin Beaumont: Still no sign of BlueKeep in the wild]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Kevin Beaumont: Still no sign of BlueKeep in the wild
Home » Forums » Newsletter and Homepage topics » Kevin Beaumont: Still no sign of BlueKeep in the wild
- This topic has 7 replies, 6 voices, and was last updated 5 years, 11 months ago by
anonymous.
Tags: BlueKeep
AuthorTopicViewing 2 reply threadsAuthorReplies-
Geo
AskWoody PlusJuly 18, 2019 at 11:40 am #1876534In case you were wondering, Kevin Beaumont hasn’t yet detected any BlueKeep infections:
Why Microsoft’s BlueKeep Bug Hasn’t Wreaked Havoc—Yet | WIRED Further information on BlueKeep.
-
Steve S
AskWoody LoungerJuly 18, 2019 at 11:57 am #1876539I got a question and this might be the best place to put it.
First BlueKeep is CVE 2019-0708
https://en.wikipedia.org/wiki/BlueKeep
I am now going to explain why that is important. Here is ms advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708
Using Windows 7 Sp1 32 bit as example. The Kb’s are 4499164 and 4499175.
Starting with 4499175. https://support.microsoft.com/en-us/help/4499175/windows-7-update-kb4499175
Note this line:
“Provides protections against a new subclass of speculative execution side-channel vulnerabilities, known as Microarchitectural Data Sampling, for 64-Bit (x64) versions of Windows (CVE-2019-11091, CVE-2018-12126, CVE-2018-12127, CVE-2018-12130). Use the registry settings as described in the Windows Client and Windows Server articles. (These registry settings are enabled by default for Windows Client OS editions, but disabled by default for Windows Server OS editions).”
First this is talking about 64 bit not 32bit. Second no mention of CVE 2019-0708 (BlueKeep)
Same in 4499164: https://support.microsoft.com/en-us/help/4499164/windows-7-update-kb4499164
Also let check security only for 64 bit. which are the same exact KB’s
One more part
the page has this: “For more information about the resolved security vulnerabilities, please refer to the Security Update Guide.” Lets do that:
https://portal.msrc.microsoft.com/en-us/security-guidance
Searching that page again has no mention of CVE 2019-0708. I checked the listed under
If this was really patched, why no mention above in either the Security Update Release notes or KB pages?
-
woody
Manager -
Alex5723
AskWoody PlusJuly 18, 2019 at 1:18 pm #1876582If this was really patched, why no mention above in either the Security Update Release notes or KB pages?
It is mentioned here with list of updates including Win7 32bit kb4499164 & kb4499175
CVE-2019-0708 | Remote Desktop Services Remote Code Execution Vulnerability
Security Vulnerability
Published: 05/14/2019
MITRE CVE-2019-0708A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would need to send a specially crafted request to the target systems Remote Desktop Service via RDP.
The update addresses the vulnerability by correcting how Remote Desktop Services handles connection requests
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708
-
Steve S
AskWoody LoungerJuly 18, 2019 at 2:25 pm #1876595You might be missing the question. BlueKeep is a big Deal. Yes I agree you can find it there, but the KB pages you think would also mention it and the Security Updates notes, it definitely should be there. Yes I see this
“The following CVEs have FAQs with additional information and may include * further steps to take after installing the updates. Please note that this is not a complete list of CVEs for this release.”.
But again notice what the security update notes are suppose to be
“For more information about the resolved security vulnerabilities, please refer to the Security Update Guide.”
as big a deal at BlueKeep is IT Should be in the Security update guide. Please find it there.
(as in notes of security patches, not general like you did.)
Also the KB’s mention some CVE, but CVE 2019-0708 is not there.
The point is why is such a Big deal not mentioned where it should be. If a users want to confirm that, yes this does patch BlueKeep, if it is not listed in the KB or the notes, how would they know for sure that, yes this is the right patch?
-
-
Speccy
AskWoody LoungerJuly 19, 2019 at 6:25 am #1876861Perhaps the answer you’re looking for lies within the Acknowledgments webpage: CVE-2019-0708 refers the UK’s National Cyber Security Centre (NCSC).
-
This reply was modified 5 years, 6 months ago by
Speccy. Reason: Edited (irrelevant, off-topic info removed)
-
This reply was modified 5 years, 6 months ago by
-
-
anonymous
GuestJuly 19, 2019 at 2:54 pm #1877000from 0 patch https://twitter.com/0patch
Quote”So while we haven’t seen massive #BlueKeep attacks yet, this modified Metasploit module got published for DOSing a range of IP addresses with BlueKeep. It now only takes one troubled soul to launch this against the Internet. Please patch or @0patch if you haven’t yet!”
And as NSA is also pushing you patch, maybe, just maybe the patch is a back door(?)
3 users thanked author for this post.
Viewing 2 reply threads - This topic has 7 replies, 6 voices, and was last updated 5 years, 11 months ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Windows 11 Insider Preview build 26200.5651 released to DEV
by
joep517
3 hours, 16 minutes ago -
Windows 11 Insider Preview build 26120.4441 (24H2) released to BETA
by
joep517
3 hours, 17 minutes ago -
iOS 26,, MacOS 26 : Create your own AI chatbot
by
Alex5723
7 hours, 12 minutes ago -
New PC transfer program recommendations?
by
DaveBoston
1 hour, 33 minutes ago -
Windows 11 Insider Preview Build 22631.5545 (23H2) released to Release Preview
by
joep517
11 hours, 17 minutes ago -
Windows 10 Build 19045.6029 (22H2) to Release Preview Channel
by
joep517
11 hours, 18 minutes ago -
Best tools for upgrading a Windows 10 to an 11
by
Susan Bradley
28 seconds ago -
The end of Windows 10 is approaching, consider Linux and LibreOffice
by
Alex5723
5 hours, 34 minutes ago -
Extended Windows Built-in Disk Cleanup Utility
by
bbearren
9 hours, 27 minutes ago -
Win 11 24H2 June 2025 Update breaks WIFI
by
dportenlanger
1 day, 6 hours ago -
Update from WinPro 10 v. 1511 on T460p?
by
CatoRenasci
4 hours, 11 minutes ago -
System Restore and Updates Paused
by
veteran
1 day, 8 hours ago -
Windows 10/11 clock app
by
Kathy Stevens
19 hours, 53 minutes ago -
Turn off right-click draw
by
Charles Billow
1 day, 12 hours ago -
Introducing ChromeOS M137 to The Stable Channel
by
Alex5723
1 day, 15 hours ago -
Brian Wilson (The Beach Boys) R.I.P
by
Alex5723
9 hours, 26 minutes ago -
Master patch listing for June 10, 2025
by
Susan Bradley
1 day, 17 hours ago -
Suggestions for New All in One Printer and a Photo Printer Windows 10
by
Win7and10
20 hours, 2 minutes ago -
Purchasing New Printer. Uninstall old Printer Software First?
by
Win7and10
1 day, 23 hours ago -
KB5060842 Issue (Minor)
by
AC641
11 hours, 16 minutes ago -
EchoLeak : Zero Click M365 Copilot leak sensitive information
by
Alex5723
2 days, 6 hours ago -
24H2 may not be offered June updates
by
Susan Bradley
22 hours, 53 minutes ago -
Acronis : Tracking Chaos RAT’s evolution (Windows, Linux)
by
Alex5723
2 days, 18 hours ago -
June 2025 updates are out
by
Susan Bradley
17 minutes ago -
Mozilla shutting Deep Fake Detector
by
Alex5723
3 days, 9 hours ago -
Windows-Maintenance-Tool (.bat)
by
Alex5723
2 days, 18 hours ago -
Windows 11 Insider Preview build 26200.5641 released to DEV
by
joep517
3 days, 12 hours ago -
Windows 11 Insider Preview build 26120.4250 (24H2) released to BETA
by
joep517
3 days, 12 hours ago -
Install Office 365 Outlook classic on new Win11 machine
by
WSrcull999
3 days, 12 hours ago -
win 10 to win 11 with cpu/mb replacement
by
aquatarkus
3 days, 4 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.