Since its advent in May 2019, BlueKeep (CVE-2019-0708) has been observed to pose risks to information security worldwide. It is a vulnerability associated with a wide range of Microsoft operating systems that affords a bad actor leverage to remotely execute malicious code on affected devices. Remediation involves updating to the latest Microsoft security patches released to mitigate BlueKeep. Sectors that use Microsoft products extensively and persist in using outdated software are particularly susceptible to this threat.
In the wild, BlueKeep was observed to have provided a launchpad for virtual-currency-mining attacks. More specifically, BlueKeep is associated with the Remote Desktop Protocol (RDP), a Windows service that allows remote access to users’ desktop environments over the Internet. RDP itself has been a starting point for multiple ransomware attacks as recently in April and May 2020. Microsoft issued a number of statements alerting users to the prospect of more BlueKeep-based attacks and urging them to patch their vulnerable operating systems.
Bitsight started tracking BlueKeep in May 2019, and published this blog post in August 2019, providing an in-depth analysis of the initial findings. This post revisits BlueKeep a year after its emergence as a worldwide threat.
The Number of Affected Systems Has Dropped, but Only to About Half of Peak Levels
Bitsight is able to observe devices with vulnerabilities like BlueKeep using its proprietary Internet-scale scanner technology. Figure 1 illustrates year-long trends observed since the emergence of BlueKeep in May 2019. An increase of vulnerable observations followed the initial detections until July 2019, which was the height of the observation levels, followed by a gradual decline. It should be clarified that the increase in observations between May and July 2019 is not due to more systems being affected by BlueKeep. Rather, the increase signifies the scaling and maturation of Bitsight’s observational capabilities for BlueKeep deployed in rapid response to the emergence of the threat in May. A year after its emergence, i.e. in May 2020, BlueKeep vulnerability observations remained around 52% of the peak count observed in July 2019.

Figure 1 Monthly Observations of BlueKeep-Affected Internet Protocol (IP) Addresses Around the World.
Even after a year has elapsed, observations of BlueKeep-affected systems have dropped by only about half of their peak levels. Remediation efforts have only been about 48% effective.
While it is heartening to see that the vulnerability is on a decline, remediation efforts seem to have tapered off with only half the problem solved.
On Average, Roughly One-Third of Affected Entities May Not Have Resolved Their Vulnerable State After One Year
Considering sector-wise data from Table 1, entities affected by BlueKeep have failed to resolve their vulnerability in 19% to 52% of cases as of May 2020. The median rate of unresolved vulnerability at the entity-level per sector is approximately 36%, or approximately one-third. The best remediation performances are seen from the Legal, Insurance.and Healthcare/Wellness sector. The worst performance is seen from the Utilities sector, followed by the Technology sector at a close second. Government/Politics and Aerospace/Defense are notable sectors with performance nearing median values. The Telecommunications sector provides some insights into the behavior of private users. A few interesting trends are demonstrated by the Consumer Goods and Technology sectors, where remediation efforts seem to have affected sharp drops in the count of vulnerable systems, but failed to eliminate them completely. Subsequent sections provide more detailed reviews of these.

Table 1 Sector-Wise Details on BlueKeep Vulnerability and Remediation with Salient Details Highlighted.
Some sectors are high-performing in their remediation efforts, while others are mediocre when compared to median performance values. A few sectors adopt ineffective remediation efforts, reducing vulnerable systems significantly, but failing to purge themselves of BlueKeep entirely. Home-user data is a dominant component of Telecommunications sector observations. Details are available in the text.
Legal, Insurance, and Healthcare Sectors Take Effective Measures to Tackle BlueKeep
Around the first anniversary of BlueKeep in May 2020, only three sectors -- Legal, Insurance, and Healthcare/Wellness -- have less than 1% of their respective entities vulnerable to the issue. These sectors also have smaller retention rates of vulnerable systems (24-37%) compared to the median for all sectors (42%). Details are available in Table 1.
Given the recent COVID-19 pandemic, the Healthcare sector’s focus on mitigating the threat of BlueKeep is highly commendable. COVID-19 may have also increased claims volume for the Insurance sector as a result of various unforeseen losses to businesses worldwide.
Government and Defense Entities Have a Mediocre Showing
With elections in the United States scheduled in 2020 and various media reports on the likelihood of interference from foreign adversaries, cybersecurity performance of the Government/Politics sector is under close scrutiny. Another related sector is Aerospace/Defense.
Both sectors emerge as mediocre performers based on the data in Table 1. While 40% of Government/Politics entities affected by BlueKeep continue to be vulnerable in May 2020, the number for the Aerospace/Defense sector is around 38%. For comparison, the median is around 35%. In terms of proportion of vulnerable systems in May 2020 relative to the July 2019 peak, both sectors perform worse than the median of 42%. In May 2020, vulnerable IP address counts in the Government/Politics sector remain at 51% relative to July 2019, while this value is a whopping 62% for the Aerospace/Defense sector.
Some Entities in the Utilities Sector Fare Worse on BlueKeep Anniversary Than at the Height of the Issue
In Table 1, all sectors other than Utilities have lower rates of vulnerability in May 2020 than in July 2019 -- both for systems and entities. Although the number of affected entities in the Utilities sector is seen to have gone down over time, the number of affected systems is observed to have surged past the levels seen in July 2019. It is possible that one or more entities have failed to do their due diligence and deployed new BlueKeep-vulnerable systems around early 2020.
Trends seen in Figures 2.a shed more light on this. The number of vulnerable systems reached their initial peak for the Utilities sector in July 2019 followed by a decline. Oddly, near the beginning of 2020, a resurgence takes place, surpassing the July 2019 peak. Worse still, the vulnerable system counts seem to have stabilized at these higher levels. From Figure 2.b, it is apparent that the surge in vulnerable systems near the beginning of 2020 did not impact the count of vulnerable entities, which seems to have declined from a peak in June 2019 and equilibrated to a steady value around the beginning of 2020. 
Figure 2.a Monthly Observations of BlueKeep-Affected Systems for the Utilities Sector.
The initial peak around July 2019 seems to have subsided, only to be revived near the beginning of 2020 and surging past the initial peak. Vulnerability levels seem to have remained heightened since.
Figure 2.b Monthly Observations of BlueKeep-Affected Entities for the Utilities Sector.
The peak of vulnerable entities occurred around June 2019 and declined. Vulnerability rates seem to have stabilized in the few months leading up to the anniversary in May 2020.
Private-Use Consumer Devices Continue to be Vulnerable on Internet-Service-Provider Networks
The Telecommunications sector is an interesting outlier for Bitsight observations by virtue of the fact that it subsumes Internet Service Providers (ISPs). The network footprint for ISPs includes rich details on the behavior of end-users who subscribe to their Internet service.







