Description
The National Security Agency (NSA) has released a cybersecurity advisory for CVE-2019-0708 (BlueKeep) vulnerability. Although Microsoft has issued a patch, there is a large possibility that millions of computers have not been patched and are exposed to the vulnerability. It is recommended that you take the necessary precautions by ensuring your products are always updated.
CVE-2019-0708 know as BlueKeep, is a vulnerability in Remote Desktop Services (RDS) on legacy versions of the windows operating system.
Affected Systems
Listed below are the following versions of Windows affected:
Mitigation Actions
The NSA urges everyone to invest the time and resources to know their network and ensure operating systems running on the affiliated network has the latest patches installed.
To address CVE-2019-0708, it is advised to immediately apply the following patches for the respective affected versions of windows listed below:
Given that large networks patch and upgrade have been issued against this threat, there are additional measures that can be considered as described in the Microsoft CVE-2019-0708 security advisory.
Note that Windows 10 systems are already protected from this vulnerability, as it only affects the older versions of windows listed above.
For more information on the CVE-2019-0708 security advisory you can follow these URLs:
https://support.microsoft.com/en-us/help/4500705/customer-guidance-for-cve-2019-0708
Reference
NSA Release Advisory on BlueKeep vulnerability (US-Cert)