/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft patches four wormable BlueKeep-like bugs in Remote Desktop Service, two of which can be exploited remotely without authentication or user interaction

Most Microsoft Windows (ab)users probably welcome the monthly ritual of applying security updates about as much as they look forward …

Krebs on Security Brian Krebs

Context & Ripple Effects

Two months after Microsoft's warning about a WannaCry-style flaw that could spread through Remote Desktop Service — and a researcher's count of roughly a million older Windows devices still exposed to BlueKeep — the August update cycle brings four more wormable holes in the same component. The difference in severity: two of these can be triggered remotely with no authentication and no user interaction, removing even the phishing step most exploits need.

The BlueKeep episode established the playbook — pre-announcement, patches extended to out-of-support Windows versions, and a visible spike in port scanning as attackers hunted exposed RDS endpoints. These four bugs land into exactly that environment, with the scanning infrastructure already warmed up.

First-order effects

  • Windows administrators face an urgent patching window on Remote Desktop Service, with internet-exposed RDS hosts the priority since the pre-auth flaws need no credentials or user action to exploit.
  • Microsoft has to repeat the BlueKeep maneuver of shipping fixes for unsupported Windows versions, since the wormable-RDS risk profile is what justified that exceptional step in May.

Second-order effects

  • Port-scanning activity against RDS endpoints, already elevated during the BlueKeep episode per the related coverage, gives attackers a ready-made target map for these new flaws before most fleets are patched.
  • Security teams that left RDS reachable after BlueKeep now face a second forcing event in one summer, accelerating moves to put remote desktop behind VPNs or gateways rather than patch-and-pray.

Third-order effects

  • If wormable remote-service bugs keep arriving on this cadence, exposing administrative protocols like RDS directly to the internet becomes untenable as an architecture, pushing the default toward brokered access — the same logic that turned WannaCry-class events into lasting segmentation projects.
  • Microsoft's willingness to patch end-of-life Windows for BlueKeep sets a precedent each new wormable RDS bug extends, blurring the vendor's line between supported and abandoned fleets whenever the blast radius is network-wide.

The trend: Self-propagating threats against remote-access services are turning Microsoft's monthly patch rhythm into the primary defense line for Windows fleets, with each wormable bug testing how quickly exposed RDS disappears from the open internet.

Discussion

  • @msftsecresponse @msftsecresponse on x
    August 2019 Security Update includes fixes for wormable RCE vulnerabilities in Remote Desktop Services (RDS), affecting all in-support versions of Windows. These should be patched quickly. For more information, see https://msrc-blog.microsoft.com/ ...
  • @daveaitel @daveaitel on x
    So it'll be ironic if the GCHQ VEP killed a RDP bug because it only affect old boxes but then MS audited all of RDP and killed one of their goto new hotness bugs. (Another good reason not to kill bugs)
  • @metr0 Justin Campbell on x
    August Patch Tuesday includes fixes for our internal finds in RDP, including RCE and remote info disclosure, and affecting Win 10 latest. The team successfully built a full exploit chain using some of these, so it's likely someone else will as well. Patch and enable NLA. https://…
  • @arstechnica @arstechnica on x
    A trio of wormable bugs in newer versions of Windows needs your attention now http://arstechnica.com/... by @dangoodin001
  • @n0x08 @n0x08 on x
    This x💯 - Justin's team found these vulns, and as leet as they are if they can find them, someone else can reverse the patches. https://twitter.com/...
  • @briankrebs @briankrebs on x
    Most Microsoft Windows users probably welcome #PatchTuesday about as much as they look forward to going to the dentist: It always seems like you were there just yesterday, and you never quite know how it's all going to turn out. https://krebsonsecurity.com/ ...
  • @goretsky Aryeh Goretsky on x
    Four wormable bugs in newer versions of Windows need your attention now https://arstechnica.com/...
  • @thezdi Zero Day Initiative on x
    August heats up with a large group of patches from #Adobe and #Microsoft. Join @dustin_childs as he breaks down the details and shows which bugs are potentially wormable. https://www.zerodayinitiative.com/ ... #PatchTuesday
  • @dangoodin001 Dan Goodin on x
    Bluekeep Redux, only worse. Updated to report there are 4 wormable flaws, all in Remote Desktop Services of Windows 10 and other newer versions of Windows. Patch now, if at all possible. If not, make sure Network Level Authentication is on or all external and internal systems. ht…
  • @campuscodi Catalin Cimpanu on x
    Microsoft warns of two new ‘wormable’ flaws in Windows Remote Desktop Services -CVE-2019-1181 and CVE-2019-1182 -impact RDS, but not RDP -both are wormable RCEs -@GossiTheDog hasn't given them nicknames (yet 😜) https://www.zdnet.com/... https://twitter.com/...