Full Report
Microsoft has released updates for Windows XP, Windows 7, Windows Server 2008, and Windows Server 2008 R2 to fix a vulnerability in the Remote Desktop Service. The vulnerability could allow an unauthenticated remote attacker to execute arbitrary code in the target system if the system exposes the service to the network. Some Siemens Healthineers software products are affected by this vulnerability. The exploitability of the vulnerability depends on the specific configuration and deployment environment of each product. Siemens Healthineers recommends installing the appropriate security patches released by Microsoft. The compatibility of Microsoft security patches with products from Siemens Healthineers that are beyond their End of Support date cannot be guaranteed.
Analysis Summary
# Vulnerability: Remote Desktop Services Remote Code Execution (BlueKeep)
## CVE Details
- **CVE ID:** CVE-2019-0708
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-416 (Use After Free)
## Affected Systems
- **Products:**
- Microsoft Windows Operating Systems
- Siemens Healthineers software products utilizing affected Windows versions
- **Versions:**
- Windows XP (all service packs)
- Windows 7 (all service packs)
- Windows Server 2008
- Windows Server 2008 R2
- **Configurations:** Systems where Remote Desktop Services (RDS) is enabled and exposed to the network without Network Level Authentication (NLA).
## Vulnerability Description
This is a "wormable" Remote Code Execution (RCE) vulnerability in Remote Desktop Services (formerly known as Terminal Services). The flaw exists in the way the service handles specially crafted requests via the RDP protocol. An attacker who successfully exploits this vulnerability could execute arbitrary code on the target system with system-level privileges. Because this vulnerability occurs pre-authentication and requires no user interaction, it can be used by malware to spread from vulnerable computer to vulnerable computer in a manner similar to the WannaCry attacks of 2017.
## Exploitation
- **Status:** Exploited in the wild; PoC available.
- **Complexity:** Low
- **Attack Vector:** Network
## Impact
- **Confidentiality:** Total
- **Integrity:** Total
- **Availability:** Total
## Remediation
### Patches
- **Microsoft Security Updates:** Apply patches for Windows 7, Windows Server 2008, and 2008 R2 via Windows Update or the Microsoft Update Catalog.
- **Out-of-Band Patches:** Microsoft has released rare security updates for "End of Life" systems including Windows XP and Windows Server 2003, available via the Microsoft Download Center.
- **Siemens Healthineers:** Users should apply the Microsoft patches corresponding to the OS underlying their Siemens software. Note: Compatibility is not guaranteed for products beyond their "End of Support" date.
### Workarounds
- **Disable RDS:** Disable Remote Desktop Services if they are not required for business operations.
- **Enable NLA:** Enable Network Level Authentication (NLA) on systems running supported editions of Windows 7, Windows Server 2008, and Windows Server 2008 R2. This forces an attacker to authenticate before the vulnerability can be triggered.
- **Block Port 3389:** Block Transmission Control Protocol (TCP) port 3389 at the enterprise perimeter firewall.
## Detection
- **Indicators of Compromise:** High volume of RDP traffic on port 3389; unexpected system crashes (BSOD) in `termdd.sys`.
- **Detection methods and tools:**
- Use vulnerability scanners (e.g., Nessus, OpenVAS) with updated plugins for CVE-2019-0708.
- Monitor network traffic for anomalous RDP channel requests (specifically the "MS_T120" channel).
## References
- **Microsoft Advisory:** hxxps[://]portal[.]msrc[.]microsoft[.]com/en-US/security-guidance/advisory/CVE-2019-0708
- **Siemens Healthineers Security:** hxxps[://]www[.]siemens-healthineers[.]com/support-documentation/cybersecurity