Windows bug BlueKeep

Discover How Volico Can Protect Your Business Against Microsoft’s RDP BlueKeep Exploit

What is the BlueKeep RDP vulnerability?

Microsoft’s May 2019 security patch fixed a remote code execution (RCE) bug in the Remote Desktop Protocol (RDP) service.

An unauthenticated attacker could send malformed, malicious RDP messages to a target server. Those messages reached the server through the system-level message service on the MS_T120 protocol. A use-after-free vulnerability triggered a page 0 overwrite, so the attacker’s code ran at the ring0 administrator level.

A successful exploit let the attacker run arbitrary code with administrator privileges on the remote machine. Attackers reportedly exploited the bug before it became public. It also carries the identifier CVE-2019-0708.

Researchers traced the flaw to the way RDP handles shared sessions, specifically the ITU-T T.128 sharing protocol. T.128 is an OS-agnostic protocol built for point-to-multipoint communication, the kind used in teleconferencing.

At the core of the vulnerability sits a static channel named “MS_T120.” Although Microsoft never intended this, an attacker can bind the channel outside its standard slot.

How the MS_T120 channel opens the door

Microsoft reserves the MS_T120 channel for internal use. It should never accept messages from outside sources, but BlueKeep let it.

Remote desktop service packs in many components. Multiple non-user-privileged DLLs cross-call kernel-mode drivers whenever an RDP session runs. A specially crafted message to the RDP server can trigger a use-after-free vulnerability inside TERMDD.SYS, the ring0 (administrator) driver.

RDP also relies on static virtual channels, or SVC. SVC handles interprocess communication between the operating system (ring0, host) and the user (non-privileged). These channels handle components like shared printing and other user extensions. The standard Microsoft RDP build offers redirection (RDPDR), clipboard sharing (CLIPRDR), and print spooler sharing. In addition, an API lets developers write their own modules for additional channels.

Step by step: how the exploit runs

Every RDP session loads two default modules from MS_T120 just to begin. Under normal, non-exploitive conditions, a client never generates or crafts system-level calls to other RDP hosts. The RDP core system handles those calls internally when a connection starts.

To exploit MS_T120, the attacker sends a series of non-NLA messages to the RDP protocol at the chosen target. RDPWSX.DLL, a user-mode component, reads those messages on the victim’s machine. It spawns a thread that loops in the ioThreadRead() function. The thread writes to the RDP page table, then waits to pass input and output to TERMDD.SYS, the ring0 (administrator) driver.

The attacker first completes the standard multi-step handshake between server and client. Then the attacker sends messages to the individual channels requested for binding, including the malicious channel at page 0.

In practice, the exploit waits until an I/O pointer reaches a function called CTS (control channel structure). At that point, the system saves the attacker’s data in a high-level pointer table called the channel pointer. Every RDP connection starts by checking that pointer table. As a result, the server reads the attacker’s payload first instead of running its normal startup functions.

Once the attacker exploits the RDP stack this way, a use-after-free vulnerability in the TERMDD.SYS kernel driver kicks in. It forces the RDP service to read data from the MS_T120 pointer, data the attacker now controls remotely. After the payload lands on the remote host, the attacker can execute code on the target with system privileges.

Ready to learn how to protect your business against BlueKeep?

Volico Data Centers offers a Managed VPN Firewall that uses industry-standard encryption. It builds a trust rule between you and every server in our facility. Once you connect, the Volico VPN+Firewall tunnels encrypted data between you and your server on specific ports only. That protects you from this vulnerability.

Packets sent over a public network this way stay unreadable without the proper decryption keys. ACL rules on open ports stop anyone from exposing or changing the data in transit. The VPN also runs a data integrity check, typically a message digest that confirms nothing changed along the way.

Volico’s Managed VPN Firewall gives you the strongest protection against the latest threats, with industry-leading performance.

• Call: (305) 735-8098
• Chat with a member of our team to discuss which solution best fits your needs.

Share this blog

About cookies on Volico.com

Volico Data Centers use cookies to collect and analyse information on site performance and usage. This site uses essential cookies which are required for functionality.  More detail is available in our privacy policy. Learn more