{"id":31748,"date":"2019-11-11T15:12:11","date_gmt":"2019-11-11T15:12:11","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/30669\/BlueKeep-Exploit-To-Get-Fix-For-Its-BSOD-Problem.html"},"modified":"2019-11-11T15:12:11","modified_gmt":"2019-11-11T15:12:11","slug":"bluekeep-exploit-to-get-fix-for-its-bsod-problem","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\/","title":{"rendered":"BlueKeep Exploit To Get Fix For Its BSOD Problem"},"content":{"rendered":"<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet3.cbsistatic.com\/hub\/i\/2019\/11\/11\/8b66182d-80e4-4ca2-a4fe-dfbbb92b7501\/acf23dab38fedd096a1442d1f5b1d36d\/exploit-globe-code-cyber.jpg\" class alt=\"exploit-globe-code-cyber.jpg\"><\/span><\/p>\n<p>Currently, the only public proof-of-concept exploit code for the infamous BlueKeep vulnerability is a module for the Metasploit penetration testing framework.<\/p>\n<p>The BlueKeep Metasploit module was put together from a proof-of-concept code donated by RiskSense security researcher Sean Dillon (<a href=\"https:\/\/twitter.com\/zerosum0x0\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">@zerosum0x0<\/a>) over the summer.<\/p>\n<p>While the exploit works, it has a downside, namely that on some systems it can crash the target with a Blue Screen of Death (BSOD) error, instead of granting the attackers a remote shell.<\/p>\n<p>This BSOD error is how security researcher Kevin Beaumont discovered the first BlueKeep-based attacks in the real-world last week after he noticed that 10 of his 11 RDP honeypots were down with a BSOD error.<\/p>\n<p>However, this week, the BlueKeep Metasploit module will get a fix for this bug. The fix removes the BSOD error and makes BlueKeep attacks more reliable.<\/p>\n<h3>BlueKeep was crashing because of the Meltdown patch<\/h3>\n<p>In an interview with <em>ZDNet<\/em> over the weekend, Dillon said the root cause of the BSOD errors was Microsoft&#8217;s patch for the Meltdown Intel CPU vulnerability.<\/p>\n<p>&#8220;From looking at screenshots of <a href=\"https:\/\/www.malwaretech.com\/2019\/09\/bluekeep-a-journey-from-dos-to-rce-cve-2019-0708.html\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">the analysis Marcus &#8216;MalwareTech&#8217; Hutchins did<\/a>, we know code execution was achieved and that the honeypots were crashing because the exploit did not support kernels with Meltdown,&#8221; Dillon told <em>ZDNet<\/em>.<\/p>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_zd_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\">\n<\/section>\n<p>&#8220;The future BlueKeep Metasploit exploit will support kernels patched for Meltdown and does not even need a KVA Shadow mitigation bypass,&#8221; he said.<\/p>\n<p><em>[KVA Shadow is the technical name that Microsoft gave to the Meltdown patch. <a href=\"https:\/\/msrc-blog.microsoft.com\/2018\/03\/23\/kva-shadow-mitigating-meltdown-on-windows\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">See here for details<\/a>.]<\/em><\/p>\n<p>The new BlueKeep exploit changes the exploit routine early in a BlueKeep attack, so a Meltdown patch bypass isn&#8217;t even needed. Diving deeper into the technical details, Dillon told <em>ZDNet<\/em>:<\/p>\n<p>&#8220;For the [BlueKeep] exploit payload to transition from kernel mode to a traditional user-mode payload (such as reverse TCP shell callback), we were changing the system call register in a way that was not allowed by the Meltdown KVA Shadow mitigation. After writing a bypass for the KVA Shadow mitigation, it was pointed out that the exploit payload could be written without needing to hook the system call at all. The need for a Meltdown bypass is actually unnecessary and part of wrong assumptions early on in the exploit development That is the fix that will be going in.&#8221;<\/p>\n<p>Dillon expects the Metasploit project to update the BlueKeep module <a href=\"https:\/\/github.com\/rapid7\/metasploit-framework\/pull\/12553\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">later this week<\/a>. A technical deep-dive into the root cause of the BlueKeep BSOD is also available on Dillon&#8217;s personal blog, <a href=\"https:\/\/zerosum0x0.blogspot.com\/2019\/11\/fixing-remote-windows-kernel-payloads-meltdown.html#kva_conclusion\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">here<\/a>.<\/p>\n<h3>Some perspective from MalwareTech<\/h3>\n<p>What this means for all of us is pretty obvious. BlueKeep&#8217;s public exploit is getting more reliable, meaning attackers have a higher chance of breaking into a company that runs at least one vulnerable system.<\/p>\n<p>As Hutchins pointed out <a href=\"https:\/\/twitter.com\/MalwareTechBlog\/status\/1192926816370970625\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">in a Twitter thread<\/a> last week, the cyber-security community has focused too much on Microsoft&#8217;s initial warning that BlueKeep could be used to create &#8220;wormable malware.&#8221;<\/p>\n<p>The result was that everybody missed the point that even if attackers don&#8217;t create a BlueKeep-based worm, BlueKeep is still a major threat and should not be ignored.<\/p>\n<p>&#8220;I&#8217;m not really worried about a worm, what I&#8217;m worried about is something that could be already happening,&#8221; Hutchins said.<\/p>\n<p>&#8220;Most BlueKeep vulnerable devices are servers. Generally speaking, Windows servers have the ability to control devices on the network. Either they&#8217;re domain admin, have network management tools installed, or share the same local admin credentials with the rest of the network. By compromising a network server, it is almost always extremely easy to use automated tooling to pivot internally (Ex: have the server drop ransomware to every system on the network),&#8221; he added.<\/p>\n<p>&#8220;The real risk with BlueKeep is not a worm. A worm is pointless and noisy. Once an attacker is on the network, they can do far more damage with standard automated tools than they could ever do with BlueKeep,&#8221; Hutchins said.<\/p>\n<p>&#8220;Remember all those news stories about entire networks being ransomwared? That starts with a single system being hacked. Not even a server, a normal, non admin, client system. Attackers don&#8217;t need worms.<\/p>\n<p>&#8220;People need to stop worrying about worms and start worrying about basic network security. Firewall your servers off from the internet, learn about credential hygiene. Occasionally worms happen, but every day there are entire networks compromised using only standard tools.&#8221;<\/p>\n<div class=\"twitterContainer\" readability=\"8.0358361774744\">\n<blockquote class=\"twitter-tweet\" readability=\"9.4539249146758\">\n<p lang=\"en\" dir=\"ltr\">When the news broke about BlueKeep exploitation in the wild, most of the reactions were basically &#8220;it&#8217;s not a worm, so it doesn&#8217;t matter&#8221;. I decided I&#8217;d do a thread on why that&#8217;s wrong, and why a worm isn&#8217;t even a worst case scenario.<\/p>\n<p>THREAD:<\/p>\n<p>\u2014 MalwareTech (@MalwareTechBlog) <a href=\"https:\/\/twitter.com\/MalwareTechBlog\/status\/1192926816370970625?ref_src=twsrc%5Etfw\" rel=\"noopener noreferrer\" target=\"_blank\" data-component=\"externalLink\">November 8, 2019<\/a><\/p><\/blockquote>\n<\/div>\n<h3>The BlueKeep lowdown<\/h3>\n<p>Because there&#8217;s been a flood of BlueKeep-related coverage this year, below is a summary of what you need to know. Just the essentials:<\/p>\n<ul>\n<li>BlueKeep is a nickname given to CVE-2019-0708, a vulnerability in the Microsoft RDP (Remote Desktop Protocol) service.<\/li>\n<li>BlueKeep impacts only: Windows 7, Windows Server 2008 R2, Windows Server 2008.<\/li>\n<li>Patches have been available since mid-May 2019. <a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2019-0708\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">See official Microsoft advisory<\/a>.<\/li>\n<li>On the same day it released patches, Microsoft published a blog post <a href=\"https:\/\/msrc-blog.microsoft.com\/2019\/05\/14\/prevent-a-worm-by-updating-remote-desktop-services-cve-2019-0708\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">warning about BlueKeep being wormable<\/a>.<\/li>\n<li><a href=\"https:\/\/blogs.technet.microsoft.com\/msrc\/2019\/05\/30\/a-reminder-to-update-your-systems-to-prevent-a-worm\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">Microsoft issued a second warning<\/a> about orgs needing to patch BlueKeep, two weeks later, at the end of May.<\/li>\n<li>The <a href=\"https:\/\/www.nsa.gov\/News-Features\/News-Stories\/Article-View\/Article\/1865726\/nsa-cybersecurity-advisory-patch-remote-desktop-services-on-legacy-versions-of\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">US National Security Agency<\/a>, the <a href=\"https:\/\/www.us-cert.gov\/ncas\/alerts\/AA19-168A\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">US Department of Homeland Security<\/a>, <a href=\"https:\/\/www.bsi.bund.de\/DE\/Presse\/Pressemitteilungen\/Presse2019\/Windows-Schwachstelle-RDP-150519.html\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">Germany&#8217;s BSI<\/a> cyber-security agency, the <a href=\"https:\/\/www.cyber.gov.au\/news\/protect-against-BlueKeep\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">Australian Cyber Security Centre<\/a>, and the <a href=\"https:\/\/www.ncsc.gov.uk\/report\/weekly-threat-report-31st-may-2019\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">UK&#8217;s National Cyber Security Centre<\/a> have all issued their own security alerts, trying to get companies to patch outdated computer fleets.<\/li>\n<li>Many security researchers and cyber-security firms developed fully-working BlueKeep exploits over the summer; however, nobody published the code after realizing how dangerous the exploit was, and fearing that it could be abused by malware authors.<\/li>\n<li>In July, a US company started <a href=\"https:\/\/www.zdnet.com\/article\/us-company-selling-weaponized-bluekeep-exploit\/\" target=\"_blank\" rel=\"noopener noreferrer\">selling a private BlueKeep exploit<\/a> to its customers, so they could test if their systems were vulnerable.<\/li>\n<li>In September, the developers of the Metasploit penetration testing framework <a href=\"https:\/\/www.zdnet.com\/article\/metasploit-team-releases-bluekeep-exploit\/\" target=\"_blank\" rel=\"noopener noreferrer\">published the first public BlueKeep proof-of-concept exploit<\/a>.<\/li>\n<li>In late October, malware authors started using this BlueKeep Metasploit module in a real-world campaign. Microsoft has an article about this malware campaign <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2019\/11\/07\/the-new-cve-2019-0708-rdp-exploit-attacks-explained\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">here<\/a>.<\/li>\n<li>According to BinaryEdge, there are roughly 700,000 internet-connected Windows systems that are vulnerable to BlueKeep, and have yet to receive patches.<\/li>\n<\/ul>\n<p> READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/30669\/BlueKeep-Exploit-To-Get-Fix-For-Its-BSOD-Problem.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":31749,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[8259],"class_list":["post-31748","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinemicrosoftflawpatchnsa"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>BlueKeep Exploit To Get Fix For Its BSOD Problem 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"BlueKeep Exploit To Get Fix For Its BSOD Problem 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2019-11-11T15:12:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/11\/bluekeep-exploit-to-get-fix-for-its-bsod-problem.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"490\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"BlueKeep Exploit To Get Fix For Its BSOD Problem\",\"datePublished\":\"2019-11-11T15:12:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\\\/\"},\"wordCount\":1049,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/11\\\/bluekeep-exploit-to-get-fix-for-its-bsod-problem.jpg\",\"keywords\":[\"headline,microsoft,flaw,patch,nsa\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\\\/\",\"name\":\"BlueKeep Exploit To Get Fix For Its BSOD Problem 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/11\\\/bluekeep-exploit-to-get-fix-for-its-bsod-problem.jpg\",\"datePublished\":\"2019-11-11T15:12:11+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/11\\\/bluekeep-exploit-to-get-fix-for-its-bsod-problem.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/11\\\/bluekeep-exploit-to-get-fix-for-its-bsod-problem.jpg\",\"width\":1000,\"height\":490},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,microsoft,flaw,patch,nsa\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinemicrosoftflawpatchnsa\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"BlueKeep Exploit To Get Fix For Its BSOD Problem\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"BlueKeep Exploit To Get Fix For Its BSOD Problem 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\/","og_locale":"en_US","og_type":"article","og_title":"BlueKeep Exploit To Get Fix For Its BSOD Problem 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2019-11-11T15:12:11+00:00","og_image":[{"width":1000,"height":490,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/11\/bluekeep-exploit-to-get-fix-for-its-bsod-problem.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"BlueKeep Exploit To Get Fix For Its BSOD Problem","datePublished":"2019-11-11T15:12:11+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\/"},"wordCount":1049,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/11\/bluekeep-exploit-to-get-fix-for-its-bsod-problem.jpg","keywords":["headline,microsoft,flaw,patch,nsa"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\/","url":"https:\/\/www.threatshub.org\/blog\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\/","name":"BlueKeep Exploit To Get Fix For Its BSOD Problem 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/11\/bluekeep-exploit-to-get-fix-for-its-bsod-problem.jpg","datePublished":"2019-11-11T15:12:11+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/11\/bluekeep-exploit-to-get-fix-for-its-bsod-problem.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/11\/bluekeep-exploit-to-get-fix-for-its-bsod-problem.jpg","width":1000,"height":490},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/bluekeep-exploit-to-get-fix-for-its-bsod-problem\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,microsoft,flaw,patch,nsa","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinemicrosoftflawpatchnsa\/"},{"@type":"ListItem","position":3,"name":"BlueKeep Exploit To Get Fix For Its BSOD Problem"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/31748","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=31748"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/31748\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/31749"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=31748"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=31748"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=31748"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}