Description
A security group allowing TCP 3389 from 0.0.0.0/0 or ::/0 permits RDP connection attempts from every address. Actual internet reachability also depends on the resource’s addressing, routing and listening service. The rule itself does not create a public address or authorize a login.
An internet-reachable RDP service can attract automated scanning, password guessing and attempts using stolen credentials. Restrict management access to controlled paths such as a VPN or bastion.
Potential impact
- External clients can attempt remote connections and logins when the service is reachable from the internet.
- Weak authentication or an RDP service vulnerability can allow server compromise.
Remediation
- Remove rules allowing TCP 3389 from every IPv4 or IPv6 address and allow only required administrator sources.
- Use a VPN, bastion or approved management network, and maintain authentication controls and service updates.
- Review other security groups and management ports such as SSH and WinRM. Test that intended administration succeeds and unwanted external connections are blocked.
Examples
These partial examples compare RDP source ranges for the same security group. Configure the target VPC and resource associations for the actual environment.
Before
resource "aws_security_group" "windows_admin" {
name = "allow-rdp"
description = "RDP open to the internet"
ingress {
description = "RDP from anywhere"
from_port = 3389
to_port = 3389
protocol = "tcp"
cidr_blocks = ["0.0.0.0/0"]
}
}
Every IPv4 address is allowed on TCP 3389. If the destination is internet-reachable, it can receive RDP connection attempts.
After
resource "aws_security_group" "windows_admin" {
name = "allow-rdp"
description = "RDP restricted to admin network"
ingress {
description = "RDP from admin network only"
from_port = 3389
to_port = 3389
protocol = "tcp"
cidr_blocks = ["10.20.0.0/24"]
}
}
The source is restricted to 10.20.0.0/24. Confirm that this is the approved management network rather than trusting it merely because it is private. The rule does not create a VPN or routing path.