logo

ICS Impact from Microsoft RDP Vulnerability

ID: 7afbeca4-168c-5f0c-b79d-117b65f1e7f3

STIX ID: report--7afbeca4-168c-5f0c-b79d-117b65f1e7f3

Feed Name: Dragos Blog

Threat Score
75/100

Date Published: 2019-05-15

Date Updated: 2026-04-27

...
...

Microsoft published an advisory for CVE-2019-0708 (BlueKeep), a wormable Remote Desktop Services vulnerability allowing unauthenticated kernel memory corruption and potential SYSTEM-level remote code execution; it affects older Windows versions (Windows 7/Server 2008 R2, Server 2008, 2003, XP) commonly found in ICS environments. Proof-of-concept exists, Microsoft released patches (including for EOL systems), and operators are urged to test and deploy patches—especially on DMZ jump boxes—because legacy ICS systems often delay updates and are at increased risk of large-scale wormable or ransomware outbreaks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.