In case you were wondering, Kevin Beaumont hasn’t yet detected any BlueKeep infections: https://twitter.com/GossiTheDog/status/1151510296302931969 Goo
[See the full post at: Kevin Beaumont: Still no sign of BlueKeep in the wild]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Kevin Beaumont: Still no sign of BlueKeep in the wild
Home » Forums » Newsletter and Homepage topics » Kevin Beaumont: Still no sign of BlueKeep in the wild
- This topic has 7 replies, 6 voices, and was last updated 5 years, 11 months ago by
anonymous.
Tags: BlueKeep
AuthorTopicViewing 2 reply threadsAuthorReplies-
Geo
AskWoody PlusJuly 18, 2019 at 11:40 am #1876534In case you were wondering, Kevin Beaumont hasn’t yet detected any BlueKeep infections:
Why Microsoft’s BlueKeep Bug Hasn’t Wreaked Havoc—Yet | WIRED Further information on BlueKeep.
-
Steve S
AskWoody LoungerJuly 18, 2019 at 11:57 am #1876539I got a question and this might be the best place to put it.
First BlueKeep is CVE 2019-0708
https://en.wikipedia.org/wiki/BlueKeep
I am now going to explain why that is important. Here is ms advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708
Using Windows 7 Sp1 32 bit as example. The Kb’s are 4499164 and 4499175.
Starting with 4499175. https://support.microsoft.com/en-us/help/4499175/windows-7-update-kb4499175
Note this line:
“Provides protections against a new subclass of speculative execution side-channel vulnerabilities, known as Microarchitectural Data Sampling, for 64-Bit (x64) versions of Windows (CVE-2019-11091, CVE-2018-12126, CVE-2018-12127, CVE-2018-12130). Use the registry settings as described in the Windows Client and Windows Server articles. (These registry settings are enabled by default for Windows Client OS editions, but disabled by default for Windows Server OS editions).”
First this is talking about 64 bit not 32bit. Second no mention of CVE 2019-0708 (BlueKeep)
Same in 4499164: https://support.microsoft.com/en-us/help/4499164/windows-7-update-kb4499164
Also let check security only for 64 bit. which are the same exact KB’s
One more part
the page has this: “For more information about the resolved security vulnerabilities, please refer to the Security Update Guide.” Lets do that:
https://portal.msrc.microsoft.com/en-us/security-guidance
Searching that page again has no mention of CVE 2019-0708. I checked the listed under
If this was really patched, why no mention above in either the Security Update Release notes or KB pages?
-
woody
Manager -
Alex5723
AskWoody PlusJuly 18, 2019 at 1:18 pm #1876582If this was really patched, why no mention above in either the Security Update Release notes or KB pages?
It is mentioned here with list of updates including Win7 32bit kb4499164 & kb4499175
CVE-2019-0708 | Remote Desktop Services Remote Code Execution Vulnerability
Security Vulnerability
Published: 05/14/2019
MITRE CVE-2019-0708A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would need to send a specially crafted request to the target systems Remote Desktop Service via RDP.
The update addresses the vulnerability by correcting how Remote Desktop Services handles connection requests
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708
-
Steve S
AskWoody LoungerJuly 18, 2019 at 2:25 pm #1876595You might be missing the question. BlueKeep is a big Deal. Yes I agree you can find it there, but the KB pages you think would also mention it and the Security Updates notes, it definitely should be there. Yes I see this
“The following CVEs have FAQs with additional information and may include * further steps to take after installing the updates. Please note that this is not a complete list of CVEs for this release.”.
But again notice what the security update notes are suppose to be
“For more information about the resolved security vulnerabilities, please refer to the Security Update Guide.”
as big a deal at BlueKeep is IT Should be in the Security update guide. Please find it there.
(as in notes of security patches, not general like you did.)
Also the KB’s mention some CVE, but CVE 2019-0708 is not there.
The point is why is such a Big deal not mentioned where it should be. If a users want to confirm that, yes this does patch BlueKeep, if it is not listed in the KB or the notes, how would they know for sure that, yes this is the right patch?
-
-
-
Speccy
AskWoody LoungerJuly 19, 2019 at 6:25 am #1876861Perhaps the answer you’re looking for lies within the Acknowledgments webpage: CVE-2019-0708 refers the UK’s National Cyber Security Centre (NCSC).
-
This reply was modified 5 years, 6 months ago by
Speccy. Reason: Edited (irrelevant, off-topic info removed)
-
This reply was modified 5 years, 6 months ago by
anonymous
GuestJuly 19, 2019 at 2:54 pm #1877000from 0 patch https://twitter.com/0patch
Quote”So while we haven’t seen massive #BlueKeep attacks yet, this modified Metasploit module got published for DOSing a range of IP addresses with BlueKeep. It now only takes one troubled soul to launch this against the Internet. Please patch or @0patch if you haven’t yet!”
And as NSA is also pushing you patch, maybe, just maybe the patch is a back door(?)
3 users thanked author for this post.
Viewing 2 reply threads - This topic has 7 replies, 6 voices, and was last updated 5 years, 11 months ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
I set up passkeys for my Microsoft account
by
Lance Whitney
2 hours, 10 minutes ago -
AI is for everyone
by
Peter Deegan
2 hours, 10 minutes ago -
Terabyte update 2025
by
Will Fastie
2 hours, 12 minutes ago -
Migrating from Windows 10 to Windows 11
by
Susan Bradley
2 hours, 32 minutes ago -
Lost sound after the upgrade to 24H2?
by
Susan Bradley
12 hours, 14 minutes ago -
How to move 10GB of data in C:\ProgramData\Package Cache ?
by
Alex5723
45 minutes ago -
Plugged in 24-7
by
CWBillow
20 hours, 31 minutes ago -
Netflix, Apple, BofA websites hijacked with fake help-desk numbers
by
Nibbled To Death By Ducks
1 day, 1 hour ago -
Have Copilot there but not taking over the screen in Word
by
CWBillow
22 hours, 32 minutes ago -
Windows 11 blocks Chrome 137.0.7151.68, 137.0.7151.69
by
Alex5723
2 days, 16 hours ago -
Are Macs immune?
by
Susan Bradley
14 hours, 35 minutes ago -
HP Envy and the Function keys
by
CWBillow
2 days ago -
Microsoft : Removal of unwanted drivers from Windows Update
by
Alex5723
4 hours, 5 minutes ago -
MacOS 26 beta 1 dropped support for Firewire 400/800
by
Alex5723
3 days, 4 hours ago -
Unable to update to version 22h2
by
04om
12 hours, 17 minutes ago -
Windows 11 Insider Preview Build 26100.4482 (24H2) released to Release Preview
by
joep517
3 days, 11 hours ago -
Windows 11 Insider Preview build 27881 released to Canary
by
joep517
3 days, 11 hours ago -
Very Quarrelsome Taskbar!
by
CWBillow
2 days, 21 hours ago -
Move OneNote Notebook OFF OneDrive and make it local
by
CWBillow
4 days ago -
Microsoft 365 to block file access via legacy auth protocols by default
by
Alex5723
3 days, 13 hours ago -
Is your battery draining?
by
Susan Bradley
12 hours, 55 minutes ago -
The 16-billion-record data breach that no one’s ever heard of
by
Alex5723
12 hours, 55 minutes ago -
Weasel Words Rule Too Many Data Breach Notifications
by
Nibbled To Death By Ducks
4 days, 4 hours ago -
Windows Command Prompt and Powershell will not open as Administrator
by
Gordski
6 hours, 40 minutes ago -
Intel Management Engine (Intel ME) Security Issue
by
PL1
3 days, 12 hours ago -
Old Geek Forced to Update. Buy a Win 11 PC? Yikes! How do I cope?
by
RonE22
3 days, 5 hours ago -
National scam day
by
Susan Bradley
2 days, 11 hours ago -
macOS Tahoe 26 the end of the road for Intel Macs, OCLP, Hackintosh
by
Alex5723
3 days, 8 hours ago -
Cyberattack on some Washington Post journalists’ email accounts
by
Bob99
5 days, 5 hours ago -
Tools to support internet discussions
by
Kathy Stevens
3 days, 18 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.