Pre-authentication flaws

The most severe RDP vulnerabilities are pre-authentication: memory-corruption bugs in the protocol handling that runs before a user logs in, reachable by an unauthenticated client and giving code execution as SYSTEM. Because RDP is so widely exposed, these are wormable, capable of self-propagating across networks, which is why they drew urgent, out-of-cycle patches and comparisons to the SMB worm events. They live in the pre-session code, so Network Level Authentication (which forces authentication first) blocks reaching them; an NLA-off host of the right build is exposed. The two named classes are BlueKeep and DejaBlue.

bash
# identify hosts in the affected build range with NLA off
nmap -p3389 --script rdp-ntlm-info,rdp-enum-encryption <target>   # build + NLA status
nmap -p3389 --script rdp-vuln-ms12-020 <target>                   # (older RDP DoS/vuln check)

Subtopics#

  • BlueKeep: the pre-auth RCE in the pre-NLA RDP code path.
  • DejaBlue: the follow-on pre-auth RCE class affecting newer builds.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more