Port 3389 may be exposed to all IPv4 sources

Restrict RDP administration to approved clients and controlled connection paths instead of allowing all source addresses.

Description

Allowing all sources on port 3389, used by RDP, can invite unnecessary connection attempts to an administrative service. Actual access also depends on the target's network path, RDP service and host firewall. Reachability does not bypass user authentication.

Potential impact

  • An externally reachable RDP service may receive brute-force attempts or sign-ins using leaked credentials.
  • A vulnerable service or weak account controls can increase the risk of host and data compromise.

Remediation

  • Identify the resources and administrative clients that need RDP. Allow only the required protocols and ports from approved CIDRs or supported security group references.
  • Use controlled administration paths such as a VPN rather than directly opening management ports to the internet. Review all attached groups, IPv4 and IPv6 paths, the host firewall and authentication.
  • Establish the required management path before changing rules, then test permitted and denied connections. Check authentication logs and unusual attempts on exposed services too.

Examples

Provide the actual VPC and management-client range as vpc_id and management_cidr, and configure AWS authentication in the execution environment. These alternatives manage the same group; resource attachments and management paths are separate prerequisites.

Before

yaml
- name: example ec2 group
  amazon.aws.ec2_security_group:
    name: example2
    description: an example EC2 group
    vpc_id: "{{ vpc_id }}"
    region: eu-west-1
    rules:
      - proto: tcp
        ports: 3389
        cidr_ip: 0.0.0.0/0

TCP port 3389 is allowed from every IPv4 source.

After

yaml
- name: example ec2 group
  amazon.aws.ec2_security_group:
    name: example2
    description: an example EC2 group
    vpc_id: "{{ vpc_id }}"
    region: eu-west-1
    rules:
      - proto: tcp
        ports: 3389
        cidr_ip: "{{ management_cidr }}"

Only the approved management-client range is allowed. Avoid an unnecessarily broad management_cidr and verify that it matches the actual source addresses on the management path.

References