Description
A security group rule permitting TCP 3389 from 0.0.0.0/0 includes every IPv4 source. A server running RDP with public addressing and a network path can receive unwanted external login attempts. Also review ::/0 rules in environments using IPv6.
Potential impact
- The service can receive more password-guessing attempts or remote logins using compromised credentials.
- Server vulnerabilities or authentication weaknesses can lead to system compromise and access to internal assets.
Remediation
- Restrict RDP sources to actual administrator addresses, an approved VPN or a management network. Permit only required sources within private ranges as well.
- Attach the group only to instances requiring administration, and consider supported management services or a bastion path. Verify administrator connectivity before making the change.
- Check additional permissions from other attached groups, Windows Firewall, RDP authentication and patches. Test that approved administrators can connect and other sources are blocked.
Examples
Supply an actual VPC. Instance attachment and RDP configuration are separate. 10.10.10.0/24 is an illustrative management network; replace it with approved actual addresses and prepare the required private route.
Before
Parameters:
myVPC:
Type: AWS::EC2::VPC::Id
Resources:
InstanceSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: Allow RDP from anywhere
VpcId:
Ref: myVPC
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: 3389
ToPort: 3389
CidrIp: 0.0.0.0/0
This allows RDP's TCP port from every IPv4 address. Security group permission does not grant login authorization, but it broadens the sources that can reach an accessible service.
After
Parameters:
myVPC:
Type: AWS::EC2::VPC::Id
Resources:
InstanceSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: Allow RDP only from admin network
VpcId:
Ref: myVPC
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: 3389
ToPort: 3389
CidrIp: 10.10.10.0/24
This permits only the specified management range. Membership in that range does not replace user authentication or authorization.