The most severe RDP vulnerabilities are pre-authentication: memory-corruption bugs in the protocol handling that runs before a user logs in, reachable by an unauthenticated client and giving code execution as SYSTEM. Because RDP is so widely exposed, these are wormable, capable of self-propagating across networks, which is why they drew urgent, out-of-cycle patches and comparisons to the SMB worm events. They live in the pre-session code, so Network Level Authentication (which forces authentication first) blocks reaching them; an NLA-off host of the right build is exposed. The two named classes are BlueKeep and DejaBlue.
# identify hosts in the affected build range with NLA off
nmap -p3389 --script rdp-ntlm-info,rdp-enum-encryption <target> # build + NLA status
nmap -p3389 --script rdp-vuln-ms12-020 <target> # (older RDP DoS/vuln check)
Subtopics#
- BlueKeep: the pre-auth RCE in the pre-NLA RDP code path.
- DejaBlue: the follow-on pre-auth RCE class affecting newer builds.