RDP port is open to the internet

Allow the RDP administration port only from approved management paths and sources.

Description

Allowing RDP port 3389 from every IPv4 (0.0.0.0/0) or IPv6 (::/0) address can unnecessarily broaden access to remote administration. Actual external connectivity also depends on instance addressing, network paths and the RDP service.

Potential impact

  • A reachable RDP service can face password guessing or login attempts using compromised credentials.
  • Authentication or server-security weaknesses can lead to system compromise and access to internal assets.

Remediation

  • When RDP is required, restrict sources to actual administrator addresses or management networks. Review both IPv4 and IPv6 rules.
  • Reduce direct exposure with a VPN, bastion or management service that meets your requirements. Verify the new management path before removing existing public rules.
  • Review every attached security group, the host firewall, authentication and patches. Remove RDP rules when unused and verify required management operations.

Examples

These security group examples require an actual VPC ID; they do not attach an instance or install RDP. The second example's 192.168.0.0/16 is an illustrative management range. Do not trust its entire range merely because it uses private addresses; narrow it to required actual sources.

Before

yaml
Parameters:
  myVPC:
    Type: AWS::EC2::VPC::Id
Resources:
  InstanceSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Allow rdp to client host
      VpcId:
        Ref: myVPC
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: 3389
          ToPort: 3389
          CidrIp: 0.0.0.0/0

This allows TCP 3389 from every IPv4 address. Clients with a network path can attempt an RDP connection.

After

yaml
Parameters:
  myVPC:
    Type: AWS::EC2::VPC::Id
Resources:
  InstanceSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Allow rdp to client host
      VpcId:
        Ref: myVPC
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: 3389
          ToPort: 3389
          CidrIp: 192.168.0.0/16

This restricts sources to the specified private range. Verify management clients have the required route and a legitimate need for access.

References