Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

BlueGate is the name used for two critical flaws in Windows Remote Desktop Gateway (RD Gateway), CVE-2020-0609 and CVE-2020-0610. Microsoft released fixes on January 14, 2020, before reports described proof-of-concept (PoC) exploits. The public PoC attributed to Ollypwn was reported to cause denial of service and included scanning functionality; a separate researcher claimed to have a working remote-code-execution (RCE) PoC, but had not made it public at the time.

What is BlueGate?

BlueGate refers to CVE-2020-0609 and CVE-2020-0610, vulnerabilities in Windows Server’s Remote Desktop Gateway—not a flaw in the ordinary Remote Desktop client. RD Gateway, previously called Terminal Services Gateway, routes remote desktop traffic to internal network addresses. It can avoid exposing internal RDP servers directly to the internet, but the gateway itself remains an internet-facing service that needs timely updates and careful exposure management.

Contemporary reports described the flaws as remotely exploitable memory-corruption vulnerabilities involving specially crafted RDP requests and the gateway’s UDP handling. The attack scenario was reported as pre-authentication and requiring no user interaction. BleepingComputer described the vulnerable path as limited to UDP. BleepingComputer’s January 2020 report and SecurityWeek’s coverage provide the contemporaneous details.

What did the BlueGate PoCs demonstrate?

Claim or release What was reported Publication status at the time
Ollypwn’s BlueGate PoC Denial of service; it also included scanning functionality. Publicly released.
Marcus Hutchins (MalwareTech) scanner Scanner source code for identifying potentially vulnerable gateways. Publicly released.
Luca Marcelli’s RCE PoC Marcelli claimed to have created a working remote-code-execution PoC. Reported as not yet publicly released.

These are distinct claims. The public Ollypwn PoC was described as a denial-of-service exploit, not as proof that it could execute code remotely. SecurityWeek separately reported Marcelli’s claim of a working RCE PoC that he had not yet released. The reports do not establish that the public DoS PoC achieved RCE.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which systems and network path were involved?

The affected component was RD Gateway on Windows Server, with the reported vulnerable traffic path using UDP. Published affected-version lists differed: SecurityWeek listed Windows Server 2012, 2016, and 2019, while BleepingComputer also listed Windows Server 2012 R2. Check Microsoft’s update guidance for the exact server version and build rather than relying on either news report’s list.

BleepingComputer reported that a 2020 Shodan scan found more than 15,500 internet-reachable RD Gateway hosts with UDP port 3391 open. That is a historical scan count, not a current measure of exposed or vulnerable servers.

What should administrators do?

  1. Install the applicable Microsoft security update. Microsoft issued fixes on January 14, 2020. Use the update applicable to the installed Windows Server version; Microsoft’s per-version guidance is the authority for applicability.
  2. If patching must wait, mitigate the UDP path. Contemporary guidance described disabling UDP transport or blocking the relevant UDP traffic at the firewall. BleepingComputer identified UDP port 3391 as the usual port. These are interim mitigations, not substitutes for installing the update.
  3. Review exposure of RD Gateway. Confirm which gateways are reachable from the internet and whether their configuration needs to accept UDP traffic. Keep access limited to what the service requires.

Microsoft’s advisory wording, as reproduced by BleepingComputer, said: “A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests.” This wording is quoted from the news report’s reproduction of Microsoft’s advisory; the advisory page itself was not independently verified here.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Does the 2020 report show current exploitation or exposure?

No. The cited January 2020 coverage establishes the disclosure, patch release, and contemporaneous PoC claims; it does not establish current exploitation or how many systems remain exposed today. Administrators should assess their own server versions, update status, and network exposure rather than infer present-day risk from the historical Shodan count or the existence of a PoC.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Sale
Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022
  • Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022, 3rd Edition
  • ABIS BOOK
  • Packt Publishing

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.