Microsoft issued urgent warnings over BlueKeep (CVE-2019-0708), a pre-authentication remote code execution flaw in Windows Remote Desktop Services that could be used in a wormable attack resembling WannaCry. The company released fixes for supported systems and took the unusual step of patching unsupported platforms including Windows XP, Vista, and Server 2003, warning that nearly 1 million internet-facing hosts exposing RDP on port 3389 remained vulnerable. Security researchers and vendors reported that the flaw was exploitable, with proof-of-concept and denial-of-service code already circulating, while affected systems included Windows 7, Server 2008, and Server 2008 R2; newer platforms such as Windows 8, Windows 10, and later server versions were not impacted.
Researchers and government agencies subsequently intensified calls to patch as exploit development accelerated, and Microsoft later confirmed in-the-wild exploitation of BlueKeep. Its investigation tied observed attacks to an opportunistic cryptomining campaign that scanned for exposed RDP services, used an unstable Metasploit-based BlueKeep exploit, launched staged PowerShell payloads, and installed persistent coin-mining malware on compromised machines. Microsoft said the activity caused RDP-related crashes seen in honeypots and telemetry across multiple countries, and warned that although the initial payload was a miner, the same vulnerability could be repurposed for far more destructive malware if organizations failed to patch or restrict direct RDP exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
On November 7, 2019, Microsoft disclosed details of early in-the-wild BlueKeep exploitation and explained that observed attacks were using an unstable Metasploit-based exploit to deploy cryptocurrency-mining malware. The company warned that more destructive payloads could follow and urged organizations to patch and investigate exposed hosts.
In November 2019, Microsoft, working with Kevin Beaumont and Marcus Hutchins, investigated BlueKeep exploitation after honeypot crashes and linked the activity to a campaign installing a persistent coin miner. Attackers scanned for vulnerable internet-facing RDP systems, used BlueKeep to launch staged PowerShell scripts, and operated infrastructure hosted in France, Great Britain, and Israel.
Shortly after a BlueKeep exploit module was released for Metasploit in September 2019, Microsoft telemetry began showing increased RDP-related crashes consistent with exploitation attempts. Microsoft later assessed these crashes were tied to an unstable exploit implementation.
On June 4, 2019, the U.S. National Security Agency publicly urged organizations and users to patch CVE-2019-0708. The warning reinforced concerns that the flaw could enable widespread compromise if left unaddressed.
Around May 31, 2019, Microsoft publicly warned that it was confident an exploit existed for BlueKeep and compared the risk to WannaCry. The company cited reporting that roughly 923,000 to nearly 1 million internet-connected systems remained vulnerable and urged immediate patching.
By May 20, 2019, multiple researchers and security vendors had confirmed BlueKeep could be exploited for remote code execution and warned it could spread in a wormable manner. At that time there was still no public evidence of active exploitation in the wild, but defenders were urged to patch and reduce RDP exposure.
On May 14, 2019, Microsoft issued security updates for CVE-2019-0708, a pre-authentication Remote Desktop Services flaw affecting older Windows versions. The company also released patches for unsupported systems such as Windows XP and Windows Server 2003 because of the risk of wormable abuse.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
18 references tracked. Mallory keeps watching after this page renders.
support.microsoft.com
Open sourcenacsa.gov.my
Open sourcemicrosoft.com
Open sourceforbes.com
Open sourceweb.archive.org
Open sourcezdnet.com
Open sourcesupport.microsoft.com
Open sourceportal.msrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.