Security group permits RDP from the entire internet

Limit RDP ingress to actual administrator sources and protect both authentication and the management path.

Description

A security group rule permitting TCP 3389 from 0.0.0.0/0 includes every IPv4 source. A server running RDP with public addressing and a network path can receive unwanted external login attempts. Also review ::/0 rules in environments using IPv6.

Potential impact

  • The service can receive more password-guessing attempts or remote logins using compromised credentials.
  • Server vulnerabilities or authentication weaknesses can lead to system compromise and access to internal assets.

Remediation

  • Restrict RDP sources to actual administrator addresses, an approved VPN or a management network. Permit only required sources within private ranges as well.
  • Attach the group only to instances requiring administration, and consider supported management services or a bastion path. Verify administrator connectivity before making the change.
  • Check additional permissions from other attached groups, Windows Firewall, RDP authentication and patches. Test that approved administrators can connect and other sources are blocked.

Examples

Supply an actual VPC. Instance attachment and RDP configuration are separate. 10.10.10.0/24 is an illustrative management network; replace it with approved actual addresses and prepare the required private route.

Before

yaml
Parameters:
  myVPC:
    Type: AWS::EC2::VPC::Id
Resources:
  InstanceSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Allow RDP from anywhere
      VpcId:
        Ref: myVPC
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: 3389
          ToPort: 3389
          CidrIp: 0.0.0.0/0

This allows RDP's TCP port from every IPv4 address. Security group permission does not grant login authorization, but it broadens the sources that can reach an accessible service.

After

yaml
Parameters:
  myVPC:
    Type: AWS::EC2::VPC::Id
Resources:
  InstanceSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Allow RDP only from admin network
      VpcId:
        Ref: myVPC
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: 3389
          ToPort: 3389
          CidrIp: 10.10.10.0/24

This permits only the specified management range. Membership in that range does not replace user authentication or authorization.

References