Microsoft urges to re-apply "BlueKeep" vulnerability affecting older Windows
Limited proof-of-concept code exploiting this vulnerability ("BlueKeep" or "CVE-2019-0708") has appeared online several days ago.
"Microsoft is convinced that there is an exploit that exploits this vulnerability," said Simon Pope, director of Incident Response at the Microsoft Security Response Center (MSRC). "Nearly one million computers are still vulnerable to CVE-2019-0708."
About a week ago, scans of computers vulnerable to BlueKeep have been made at a rapid pace. Microsoft has issued another warning in case the attack actually begins.
Currently, patches have been released for Windows XP, Windows Vista, Windows 7, Windows Server 2003, and Windows Server 2008. These are Windows versions vulnerable to BlueKeep attacks.
Microsoft issued its first BlueKeep warning on May 14th, when it released its May Security Patch ("Patch Tuesday"). The company described the vulnerability as having the worm's characteristics (allowing it to propagate itself).
He also warns companies of the danger of thinking that a workstation that is not connected to the Internet is safe.
Pope also warns companies about what they think is safe because they have not been seen before.
"It has been only two weeks since the fix has been released, and there are no signs of worms, so that's not a relief."
"In some cases, this vulnerability (the code that pokes it) may not be embedded in malware, but it should not be considered as such."
Currently, BlueKeep's demo exploit code published on GitHub doesn't seem as dangerous as expected. It may just crash the remote vulnerable system, not to run code on it.
However, highly skilled reverse engineers seem to have succeeded in remote code execution in proof-of-concept exploits. However, they are refusing to release exploits, concerned that they would cause the next large ransomware spread. Security vendors who have developed proof of concept exploits include Zerodium, McAfee, Kaspersky, Check Point, MalwareTech, and Valthek.
View images on Twitter

Comments
Post a Comment