Microsoft patches four wormable BlueKeep-like bugs in Remote Desktop Service, two of which can be exploited remotely without authentication or user interaction
Most Microsoft Windows (ab)users probably welcome the monthly ritual of applying security updates about as much as they look forward …
Context & Ripple Effects
Two months after Microsoft's warning about a WannaCry-style flaw that could spread through Remote Desktop Service — and a researcher's count of roughly a million older Windows devices still exposed to BlueKeep — the August update cycle brings four more wormable holes in the same component. The difference in severity: two of these can be triggered remotely with no authentication and no user interaction, removing even the phishing step most exploits need.
The BlueKeep episode established the playbook — pre-announcement, patches extended to out-of-support Windows versions, and a visible spike in port scanning as attackers hunted exposed RDS endpoints. These four bugs land into exactly that environment, with the scanning infrastructure already warmed up.
First-order effects
- Windows administrators face an urgent patching window on Remote Desktop Service, with internet-exposed RDS hosts the priority since the pre-auth flaws need no credentials or user action to exploit.
- Microsoft has to repeat the BlueKeep maneuver of shipping fixes for unsupported Windows versions, since the wormable-RDS risk profile is what justified that exceptional step in May.
Second-order effects
- Port-scanning activity against RDS endpoints, already elevated during the BlueKeep episode per the related coverage, gives attackers a ready-made target map for these new flaws before most fleets are patched.
- Security teams that left RDS reachable after BlueKeep now face a second forcing event in one summer, accelerating moves to put remote desktop behind VPNs or gateways rather than patch-and-pray.
Third-order effects
- If wormable remote-service bugs keep arriving on this cadence, exposing administrative protocols like RDS directly to the internet becomes untenable as an architecture, pushing the default toward brokered access — the same logic that turned WannaCry-class events into lasting segmentation projects.
- Microsoft's willingness to patch end-of-life Windows for BlueKeep sets a precedent each new wormable RDS bug extends, blurring the vendor's line between supported and abandoned fleets whenever the blast radius is network-wide.
The trend: Self-propagating threats against remote-access services are turning Microsoft's monthly patch rhythm into the primary defense line for Windows fleets, with each wormable bug testing how quickly exposed RDS disappears from the open internet.