In case you were wondering, Kevin Beaumont hasn’t yet detected any BlueKeep infections: https://twitter.com/GossiTheDog/status/1151510296302931969 Goo
[See the full post at: Kevin Beaumont: Still no sign of BlueKeep in the wild]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Kevin Beaumont: Still no sign of BlueKeep in the wild
Home » Forums » Newsletter and Homepage topics » Kevin Beaumont: Still no sign of BlueKeep in the wild
- This topic has 7 replies, 6 voices, and was last updated 4 years, 2 months ago by
anonymous.
Tags: BlueKeep
AuthorTopicViewing 2 reply threadsAuthorReplies-
Geo
AskWoody PlusIn case you were wondering, Kevin Beaumont hasn’t yet detected any BlueKeep infections:
Why Microsoft’s BlueKeep Bug Hasn’t Wreaked Havoc—Yet | WIRED Further information on BlueKeep.
-
Steve S
AskWoody LoungerI got a question and this might be the best place to put it.
First BlueKeep is CVE 2019-0708
https://en.wikipedia.org/wiki/BlueKeep
I am now going to explain why that is important. Here is ms advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708
Using Windows 7 Sp1 32 bit as example. The Kb’s are 4499164 and 4499175.
Starting with 4499175. https://support.microsoft.com/en-us/help/4499175/windows-7-update-kb4499175
Note this line:
“Provides protections against a new subclass of speculative execution side-channel vulnerabilities, known as Microarchitectural Data Sampling, for 64-Bit (x64) versions of Windows (CVE-2019-11091, CVE-2018-12126, CVE-2018-12127, CVE-2018-12130). Use the registry settings as described in the Windows Client and Windows Server articles. (These registry settings are enabled by default for Windows Client OS editions, but disabled by default for Windows Server OS editions).”
First this is talking about 64 bit not 32bit. Second no mention of CVE 2019-0708 (BlueKeep)
Same in 4499164: https://support.microsoft.com/en-us/help/4499164/windows-7-update-kb4499164
Also let check security only for 64 bit. which are the same exact KB’s
One more part
the page has this: “For more information about the resolved security vulnerabilities, please refer to the Security Update Guide.” Lets do that:
https://portal.msrc.microsoft.com/en-us/security-guidance
Searching that page again has no mention of CVE 2019-0708. I checked the listed under
If this was really patched, why no mention above in either the Security Update Release notes or KB pages?
-
woody
Manager -
Alex5723
AskWoody PlusIf this was really patched, why no mention above in either the Security Update Release notes or KB pages?
It is mentioned here with list of updates including Win7 32bit kb4499164 & kb4499175
CVE-2019-0708 | Remote Desktop Services Remote Code Execution Vulnerability
Security Vulnerability
Published: 05/14/2019
MITRE CVE-2019-0708A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would need to send a specially crafted request to the target systems Remote Desktop Service via RDP.
The update addresses the vulnerability by correcting how Remote Desktop Services handles connection requests
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708
-
Steve S
AskWoody LoungerYou might be missing the question. BlueKeep is a big Deal. Yes I agree you can find it there, but the KB pages you think would also mention it and the Security Updates notes, it definitely should be there. Yes I see this
“The following CVEs have FAQs with additional information and may include * further steps to take after installing the updates. Please note that this is not a complete list of CVEs for this release.”.
But again notice what the security update notes are suppose to be
“For more information about the resolved security vulnerabilities, please refer to the Security Update Guide.”
as big a deal at BlueKeep is IT Should be in the Security update guide. Please find it there.
(as in notes of security patches, not general like you did.)
Also the KB’s mention some CVE, but CVE 2019-0708 is not there.
The point is why is such a Big deal not mentioned where it should be. If a users want to confirm that, yes this does patch BlueKeep, if it is not listed in the KB or the notes, how would they know for sure that, yes this is the right patch?
-
-
-
Speccy
AskWoody LoungerPerhaps the answer you’re looking for lies within the Acknowledgments webpage: CVE-2019-0708 refers the UK’s National Cyber Security Centre (NCSC).
-
This reply was modified 3 years, 9 months ago by
Speccy. Reason: Edited (irrelevant, off-topic info removed)
-
This reply was modified 3 years, 9 months ago by
anonymous
Guestfrom 0 patch https://twitter.com/0patch
Quote”So while we haven’t seen massive #BlueKeep attacks yet, this modified Metasploit module got published for DOSing a range of IP addresses with BlueKeep. It now only takes one troubled soul to launch this against the Internet. Please patch or @0patch if you haven’t yet!”
And as NSA is also pushing you patch, maybe, just maybe the patch is a back door(?)
3 users thanked author for this post.
Viewing 2 reply threads - This topic has 7 replies, 6 voices, and was last updated 4 years, 2 months ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Microsoft’s massive Windows 11 update, featuring Copilot AI, begins rolling out
by
Alex5723
41 minutes ago -
Microsoft’s massive Windows 11 update, featuring Copilot AI, begins rolling out
by
Alex5723
42 minutes ago -
MailStore Home updates
by
Alex5723
13 hours, 8 minutes ago -
T-Mobile users say they see other people’s account information
by
Alex5723
1 day ago -
Retirement of Exchange Web Services in Exchange Online
by
Alex5723
1 day, 12 hours ago -
What Remote Desktop credentials do I use to access a MS Account computer
by
JP
1 hour, 52 minutes ago -
Office 2003 Compatibility with One Drive in Windows 11
by
langsjw
1 day, 23 hours ago -
Has KB5030219 been pulled for Windows 11 Pro for Workstations?
by
jharri46
2 hours, 7 minutes ago -
By default encryption on Apple
by
Susan Bradley
1 day, 17 hours ago -
KB5029331 Macrium/Reflect
by
fpefpe
1 day, 18 hours ago -
Windows 10 Build 19045.3513 (22H2) to Release Preview Channel
by
joep517
2 days, 5 hours ago -
Microsoft worker accidentally exposes 38TB of sensitive data in GitHub blunder
by
Nibbled To Death By Ducks
1 day, 14 hours ago -
Change CPU/Mainboard without reinstallation of OS and Apps – Win10
by
schmersa
1 day, 20 hours ago -
Mouse slows to crawl if Edge in focus
by
bryash
3 days ago -
Windows and Surface chief Panos Panay is leaving Microsoft
by
Alex5723
2 days, 14 hours ago -
Essential Office Portable
by
Microfix
3 days, 2 hours ago -
Essential Office: Disable Spell Check
by
Bob Blum
3 days, 2 hours ago -
Apple 2030
by
Will Fastie
1 day ago -
Wi-Fi 7? Why not!
by
B. Livingston
2 seconds ago -
Second city — the AI view from Washington
by
Max Stul Oppenheimer
3 days, 11 hours ago -
Zeroing in on zero days
by
Susan Bradley
1 day, 20 hours ago -
LMDE – Software Update
by
bassmanzam
1 day, 2 hours ago -
MacAfee anti virus left overs
by
Barry
20 hours, 38 minutes ago -
Google issues update for Chrome 109 (Win 7 – Server 2012r2) that fixes WebP
by
n0ads
1 hour, 24 minutes ago -
Microsoft apparently canning P2P Win32 services on Windows 11 23H2, Windows 12
by
Alex5723
3 days, 21 hours ago -
Inserting from clipboard into posting
by
WSraysig
3 days, 20 hours ago -
Background picture not invoked @ startup
by
WSraysig
1 day, 23 hours ago -
download Linux Mint most recent
by
rjacobscan
4 days, 4 hours ago -
Modify email account settings
by
metzmatt
4 days, 12 hours ago -
Microsoft’s Edge 109 updates for Windows 7 , 8, 8.1, 2012 R2 ! webP fix
by
Alex5723
5 days, 2 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2023 by AskWoody Tech LLC. All Rights Reserved.