Register Free Newsletter Plus Membership
  • Home
    • Newsletters/Alerts
    • Forums
    • About
    • MS-DEFCON System
    • Master Patch List
    • Register
    • Login
Microsoft Patch Defense Condition level 2 Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it.
SIGN IN Not a member? REGISTER PLUS MEMBERSHIP
  • Kevin Beaumont: Still no sign of BlueKeep in the wild

    Home » Forums » Newsletter and Homepage topics » Kevin Beaumont: Still no sign of BlueKeep in the wild

    • This topic has 7 replies, 6 voices, and was last updated 5 years, 11 months ago by anonymous.

    Tags: BlueKeep

    Author
    Topic
    New Reply
    woody
    Manager
    July 18, 2019 at 3:24 am #1876364

    In case you were wondering, Kevin Beaumont hasn’t yet detected any BlueKeep infections: https://twitter.com/GossiTheDog/status/1151510296302931969 Goo
    [See the full post at: Kevin Beaumont: Still no sign of BlueKeep in the wild]

    2 users thanked author for this post.
    SueW, Elly
    Reply | Quote
    Viewing 2 reply threads
    Author
    Replies
    • Geo
      AskWoody Plus
      July 18, 2019 at 11:40 am #1876534
      woody wrote:

      In case you were wondering, Kevin Beaumont hasn’t yet detected any BlueKeep infections:

      Why Microsoft’s BlueKeep Bug Hasn’t Wreaked Havoc—Yet | WIRED      Further information on BlueKeep.

      2 users thanked author for this post.
      woody, b
      Reply | Quote
    • Steve S
      AskWoody Lounger
      July 18, 2019 at 11:57 am #1876539

      I got a question and this might be the best place to put it.

       

      First BlueKeep is CVE 2019-0708

      https://en.wikipedia.org/wiki/BlueKeep

      https://www.bleepingcomputer.com/news/security/bluekeep-remote-desktop-exploits-are-coming-patch-now/

      https://answers.microsoft.com/en-us/windows/forum/all/how-install-bluekeep-patch-for-windows-7/e1582d6b-9669-408c-a58f-0f7c7c1be651

      I am now going to explain why that is important. Here is ms advisory

      https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708

      Using Windows 7 Sp1 32 bit as example. The Kb’s are 4499164 and 4499175.

      Starting with 4499175. https://support.microsoft.com/en-us/help/4499175/windows-7-update-kb4499175

      Note this line:

      “Provides protections against a new subclass of speculative execution side-channel vulnerabilities, known as Microarchitectural Data Sampling, for 64-Bit (x64) versions of Windows (CVE-2019-11091, CVE-2018-12126, CVE-2018-12127, CVE-2018-12130). Use the registry settings as described in the Windows Client and Windows Server articles. (These registry settings are enabled by default for Windows Client OS editions, but disabled by default for Windows Server OS editions).”

      First this is talking about 64 bit not 32bit. Second no mention of CVE 2019-0708 (BlueKeep)

      Same in 4499164: https://support.microsoft.com/en-us/help/4499164/windows-7-update-kb4499164

      Also let check security only for 64 bit. which are the same exact KB’s

      One more part

      the page has this:  “For more information about the resolved security vulnerabilities, please refer to the Security Update Guide.” Lets do that:

      https://portal.msrc.microsoft.com/en-us/security-guidance

      Searching that page again has no mention of CVE 2019-0708. I checked the listed under

      March https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/ac45e477-1019-e911-a98b-000d3a33a34d

      April https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/18306ed5-1019-e911-a98b-000d3a33a34d

      May https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/e5989c8b-7046-e911-a98e-000d3a33a34d

      June https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/253dc509-9a5b-e911-a98e-000d3a33c573

      and July https://portal.msrc.microsoft.com/en-us/security-guidance/releasenotedetail/48293f19-d662-e911-a98e-000d3a33c573

      If this was really patched, why no mention above in either the Security Update Release notes or KB pages?

      Reply | Quote
      • woody
        Manager
        July 18, 2019 at 12:54 pm #1876566

        Good question… and I don’t know the answer.

        Perhaps someone else here knows more of the details?

        Reply | Quote
      • Alex5723
        AskWoody Plus
        July 18, 2019 at 1:18 pm #1876582
        Steve S wrote:

        If this was really patched, why no mention above in either the Security Update Release notes or KB pages?

        It is mentioned here with list of updates including Win7 32bit kb4499164 & kb4499175

        CVE-2019-0708 | Remote Desktop Services Remote Code Execution Vulnerability
        Security Vulnerability
        Published: 05/14/2019
        MITRE CVE-2019-0708

        A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

        To exploit this vulnerability, an attacker would need to send a specially crafted request to the target systems Remote Desktop Service via RDP.

        The update addresses the vulnerability by correcting how Remote Desktop Services handles connection requests

        https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708

        Reply | Quote
        • Steve S
          AskWoody Lounger
          July 18, 2019 at 2:25 pm #1876595

          You might be missing the question. BlueKeep is a big Deal. Yes I agree you can find it there, but the KB pages you think would also mention it and the Security Updates notes, it definitely should be there. Yes I see this

          “The following CVEs have FAQs with additional information and may include * further steps to take after installing the updates. Please note that this is not a complete list of CVEs for this release.”.

          But again notice what the security update notes are suppose to be

          “For more information about the resolved security vulnerabilities, please refer to the Security Update Guide.”

          as big a deal at BlueKeep is IT Should be in the Security update guide. Please find it there.

          (as in notes of security patches, not general like you did.)

          Also the KB’s mention some CVE, but CVE 2019-0708 is not there.

          The point is why is such a Big deal not mentioned where it should be. If a users want to confirm that, yes this does patch BlueKeep, if it is not listed in the KB or the notes, how would they know for sure that, yes this is the right patch?

           

          • This reply was modified 5 years, 11 months ago by Steve S.
          • This reply was modified 5 years, 11 months ago by Steve S.
          Reply | Quote
      • Speccy
        AskWoody Lounger
        July 19, 2019 at 6:25 am #1876861

        Perhaps the answer you’re looking for lies within the Acknowledgments webpage: CVE-2019-0708 refers the UK’s National Cyber Security Centre (NCSC).

        • This reply was modified 5 years, 6 months ago by Speccy. Reason: Edited (irrelevant, off-topic info removed)
        Reply | Quote
    • anonymous
      Guest
      July 19, 2019 at 2:54 pm #1877000

      from 0 patch https://twitter.com/0patch

      Quote”So while we haven’t seen massive #BlueKeep attacks yet, this modified Metasploit module got published for DOSing a range of IP addresses with BlueKeep. It now only takes one troubled soul to launch this against the Internet. Please patch or @0patch if you haven’t yet!”

      And as NSA is also pushing you patch, maybe, just maybe the patch is a back door(?)

      https://www.nsa.gov/News-Features/News-Stories/Article-View/Article/1865726/nsa-cybersecurity-advisory-patch-remote-desktop-services-on-legacy-versions-of/

      3 users thanked author for this post.
      Speccy, columbia2011, woody
      Reply | Quote
    Viewing 2 reply threads
    Reply To: Reply #1877000 in Kevin Beaumont: Still no sign of BlueKeep in the wild

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information:




    Cancel
DON'T MISS OUT!
Subscribe to the Free Newsletter
We promise not to spam you. Unsubscribe at any time.
Invalid email address
Thanks for subscribing!

Register
Lost your password?

Plus Membership

Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.

AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.


Get Plus!

Welcome to our unique respite from the madness.

It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.

Search Newsletters

Search Forums

Advanced Search

View the Forum

  • Recent Replies
  • My Replies
  • My Active Topics
  • New Posts in the Last day
  • Private Messages
  • Knowledge Base
  • How to use the Forums
  • All Forums
  • Search for Topics

    • Most popular topics
    • Topics with no replies
    • Recently active topics
    • New posts: Last day
    • New posts: Last three days
    • New posts: Last week
    • New posts: Last month
    • Topics with most replies
    • Latest topics

    Recent Topics

    • I set up passkeys for my Microsoft account by Lance Whitney
      2 hours, 10 minutes ago
    • AI is for everyone by Peter Deegan
      2 hours, 10 minutes ago
    • Terabyte update 2025 by Will Fastie
      2 hours, 12 minutes ago
    • Migrating from Windows 10 to Windows 11 by Susan Bradley
      2 hours, 32 minutes ago
    • Lost sound after the upgrade to 24H2? by Susan Bradley
      12 hours, 14 minutes ago
    • How to move 10GB of data in C:\ProgramData\Package Cache ? by Alex5723
      45 minutes ago
    • Plugged in 24-7 by CWBillow
      20 hours, 31 minutes ago
    • Netflix, Apple, BofA websites hijacked with fake help-desk numbers by Nibbled To Death By Ducks
      1 day, 1 hour ago
    • Have Copilot there but not taking over the screen in Word by CWBillow
      22 hours, 32 minutes ago
    • Windows 11 blocks Chrome 137.0.7151.68, 137.0.7151.69 by Alex5723
      2 days, 16 hours ago
    • Are Macs immune? by Susan Bradley
      14 hours, 35 minutes ago
    • HP Envy and the Function keys by CWBillow
      2 days ago
    • Microsoft : Removal of unwanted drivers from Windows Update by Alex5723
      4 hours, 5 minutes ago
    • MacOS 26 beta 1 dropped support for Firewire 400/800 by Alex5723
      3 days, 4 hours ago
    • Unable to update to version 22h2 by 04om
      12 hours, 17 minutes ago
    • Windows 11 Insider Preview Build 26100.4482 (24H2) released to Release Preview by joep517
      3 days, 11 hours ago
    • Windows 11 Insider Preview build 27881 released to Canary by joep517
      3 days, 11 hours ago
    • Very Quarrelsome Taskbar! by CWBillow
      2 days, 21 hours ago
    • Move OneNote Notebook OFF OneDrive and make it local by CWBillow
      4 days ago
    • Microsoft 365 to block file access via legacy auth protocols by default by Alex5723
      3 days, 13 hours ago
    • Is your battery draining? by Susan Bradley
      12 hours, 55 minutes ago
    • The 16-billion-record data breach that no one’s ever heard of by Alex5723
      12 hours, 55 minutes ago
    • Weasel Words Rule Too Many Data Breach Notifications by Nibbled To Death By Ducks
      4 days, 4 hours ago
    • Windows Command Prompt and Powershell will not open as Administrator by Gordski
      6 hours, 40 minutes ago
    • Intel Management Engine (Intel ME) Security Issue by PL1
      3 days, 12 hours ago
    • Old Geek Forced to Update. Buy a Win 11 PC? Yikes! How do I cope? by RonE22
      3 days, 5 hours ago
    • National scam day by Susan Bradley
      2 days, 11 hours ago
    • macOS Tahoe 26 the end of the road for Intel Macs, OCLP, Hackintosh by Alex5723
      3 days, 8 hours ago
    • Cyberattack on some Washington Post journalists’ email accounts by Bob99
      5 days, 5 hours ago
    • Tools to support internet discussions by Kathy Stevens
      3 days, 18 hours ago

    Recent blog posts

    • I set up passkeys for my Microsoft account
    • AI is for everyone
    • Terabyte update 2025
    • Migrating from Windows 10 to Windows 11
    • Are Macs immune?
    • Is your battery draining?
    • National scam day
    • AI is good sometimes

    My Profile

    Login and Registration

    • Log In
    • Register

    Key Links

    • > Computerworld's The Microsoft Patch Lady
    • > Computerworld's Woody on Windows
    • AskWoody Knowledge Base index
    • BlockaPatch tools
    • Gift subscription for Ask Woody Newsletter
    • Microsoft Answers Forum
    • Tasks for the Weekend YouTube Channel
    June 2025
    S M T W T F S
    1234567
    891011121314
    15161718192021
    22232425262728
    2930  
    « May    

    Remembering Woody

     

    Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.

    Mastodon profile for DefConPatch
    Mastodon profile for AskWoody

     

    Home • About • FAQ • Posts & Privacy • Forums • My Account
    Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts

    Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.

    Insert/edit link

    Enter the destination URL

    Or link to existing content

      No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.