Microsoft patched four wormable Windows flaws in its RDP services this month.
Microsoft RDP Patches: CVEs; CVE-2019-1181 | CVE-2019-1182
Windows Systems affected: Windows 7 SP1, Windows Server 2008 R2 SP1, and Windows Server 2012. Also affected: Windows 8.1 and Windows Server 2012 R2. This affects all supported versions of Windows 10, including server versions.
Systems not affected: Windows XP, Windows Server 2003, and Windows Server 2008
Contact us for more details on how Volico can protect your business against remote desktop flaws.
- Call: (305) 735-8098
- Chat with a member of our team to discuss which solution best fits your needs.
- Email us at [email protected]
Overview of the Flaws
Panic over the recent BlueKeep flaw was just fading when two new Remote Desktop flaws surfaced. Both could hit your organization hard.
Wormable is the term for malware that can move laterally on its own. Once it executes on one target, it copies itself and spreads to other machines on the network. That lets it infect the whole environment without any help from an attacker.
Like BlueKeep, attackers issue specially crafted packets to manipulate values. The difference here is that the attack bypasses RDP authentication entirely, handing the attacker full remote command execution.
This triggers a memory corruption bug and opens a channel for Remote Code Execution. The attacker can then issue whatever command they want.
Microsoft rolled out a new set of RDP patches that cover these remote code execution (RCE) flaws. Like every remote command execution exploit, these flaws can pivot and propagate a second stage of attack. That is what makes them wormable. That means attackers could attach ransomware to these payloads, encrypting your entire organization’s hard drives until you pay up.
Microsoft has patched the following CVEs:
CVE-2019-1181 [PATCH AVAILABLE]
CVE-2019-1182 [PATCH AVAILABLE]
Microsoft issued the patches, and the mainstream fix rolled out within hours. We reversed the patch to see how these exploits actually work.
Mitigating These Wormable Windows Flaws
The Volico endpoint security includes a multi-layered approach for malware prevention and attacks like the above.
Sophisticated exploits like these bypass most anti-exploit, anti-worm, and anti-malware endpoint protection for a range of reasons. Volico’s stack-monitoring would have caught this one. Once detected, our endpoint protection takes the session through pre- and post-execution inspection (future-exp and past-exp). This determines its goal.
The system places that session in pre-execution inspection extract mode. It then examines the malcode’s intent and its command-and-control traffic to see what the exploit would do next.
The session replay would then utilize our proprietary machine-learning algorithm to detect files that fit a malware profile globally. Once the algorithm detects its original source, it’s then placed under the known APT and protected worldwide.
Malcode that moves beyond this detection technique then passes through our DBAF (dynamic behavioral analysis filter). DBAF looks for known malicious behavior, such as illicit registry changes or file encryption. This dynamic behavioral analysis works especially well against file-less exploits like this one and against never-before-seen ransomware.
This lets us track malicious behavior across systems as attackers move through the kill chain, for full attack lifecycle detection.
Volico’s endpoint solutions also integrate with threat intelligence feeds. That lets us correlate internal behavior with the tactics, techniques, and procedures (TTPs) behind each exploit or malware we detect. It helps us stay ahead of advanced attacks.
Deeper Overview of the Flaw
When we examined Microsoft’s patches, we found an RCE (remote command execution) flaw in the RDP/Terminal server stack. It lived in the request_to_cooperate() function call. That let attackers without credentials run arbitrary commands on remote servers with no authentication.
The server checks only a 52-byte trust value during the request-to-cooperate callback. It ignores everything else in the payload. That gap lets an attacker generate, unpack, and deliver a crafted payload straight to the session.
To stay stable, the attacker must craft a response packet whose bytes match exactly 52. That means avoiding canaries or stack-smash protections. Get that wrong, and the RDP protocol kills the session.
Reversing the patch further showed that once the attacker sent that 52-byte trust value, they could do anything.
A remote attacker can craft a payload, encode it, and deliver it during the normal RDP handshake. That payload skips authentication and runs whatever commands the attacker chooses on the target.
Once the remote server unpacks that string, it opens a use-after-free flaw. That tricks the RDP stack into a return-oriented programming (ROP) technique that skips the authentication check. This hands the attacker remote command execution on the machine.






