Law Firm's Half-Million-Dollar Security Spend Undone by Unpatched Windows Flaw
A security researcher conducting a penetration test on behalf of a national law firm ahead of an acquisition found that a smaller firm being acquired had failed to patch BlueKeep, a serious remote code execution vulnerability in Windows' Remote Desktop Protocol first identified in 2019. Despite the firm reportedly spending around half a million dollars on security software and patching efforts the previous year, the BlueKeep flaw, which affects multiple Windows versions and can spread automatically between systems, had gone unaddressed.
Using the vulnerability, the researcher gained access to the organisation's systems and discovered that passwords were stored in plain text, requiring no decryption to read. Among them was a weak password belonging to the person responsible for the firm's cybersecurity, despite attempts to disguise it with symbol substitutions.
The case highlights a common gap between spending on security tools and actually closing known vulnerabilities. Even well-resourced organisations can remain exposed if critical patches are missed and basic practices like password encryption are overlooked.