Cyber Alerts

Wormable BlueKeep Vulnerability

Verified Officially confirmed

On May 14, 2019, Microsoft has announced a new vulnerability that exists in older versions of Windows. The vulnerability could lead to new self-propagating malware that bears a striking resemblance to the infamous WannaCry that wreaked havoc on systems around the globe in 2017. The National Cyber Coordination and Command Centre (NC4) would like to advise all users of older version of Microsoft Windows to update your Windows by downloading and installing update as recommended by Microsoft to mitigate this issue.

First observed
02 Jun 2019
Last checked
31 Jul 2026
Evidence records
1
Publication state
Published

What happened?

Current assessment

On May 14, 2019, Microsoft has announced a new vulnerability that exists in older versions of Windows. The vulnerability could lead to new self-propagating malware that bears a striking resemblance to the infamous WannaCry that wreaked havoc on systems around the globe in 2017. The National Cyber Coordination and Command Centre (NC4) would like to advise all users of older version of Microsoft Windows to update your Windows by downloading and installing update as recommended by Microsoft to mitigate this issue.

Why it matters

Malicious code execution & Denial of Service

Who is affected?

Affected products and groups

  • Software: and Windows Server 2008 R2 for x64-based Systems Service Pack 1.
  • Software: The following Microsoft Windows Operating Systems: Windows XP SP3 x86
  • Software: Windows 7 for 32-bit Systems Service Pack 1
  • Software: Windows 7 for x64-based Systems Service Pack 1
  • Software: Windows Server 2003 SP2 x86
  • Software: Windows Server 2003 x64 Edition SP2
  • Software: Windows Server 2008 for 32-bit Systems Service Pack 2
  • Software: Windows Server 2008 for Itanium-Based Systems Service Pack 2
  • Software: Windows Server 2008 for x64-based Systems Service Pack 2
  • Software: Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1
  • Software: Windows XP Embedded SP3 x86
  • Software: Windows XP Professional x64 Edition SP2

What should you do now?

Actions from official guidance

For technical teams

  1. NC4 advises agencies to take the following actions: Official source
  2. Update all your Windows devices Operating Systems with the latest security patches (refer to customer guidance for CVE-2019-0708 links under Reference); Block port 3389 (RDP) inbound and possibly outbound connection (if possible) until the patch is successfully installed; and For any incidents related to this attack, please report to NC4. Official source

Which sources support it?

Evidence and official sources

  1. NACSA / NC4 Alerts and AdvisoriesOfficial source
    Wormable BlueKeep Vulnerability

    On May 14, 2019, Microsoft has announced a new vulnerability that exists in older versions of Windows. The vulnerability could lead to new self-propagating malware that bears a striking resemblance to the infamous WannaCry that wreaked havoc on systems around the globe in 2017. The National Cyber Coordination and Command Centre (NC4) would like to advise all users of older version of Microsoft Windows to update your Windows by downloading and installing update as recommended by Microsoft to mitigate this issue.

    Published 02 Jun 2019 · Retrieved 31 Jul 2026