Definition · Open Ports & Services

What is RDP?

Remote Desktop Protocol is Microsoft’s protocol for interactive remote access to Windows desktops and servers. It listens on TCP port 3389 by default, with a UDP transport also available. RDP itself is a legitimate and widely used administration tool; the problem is exposure. An RDP service answering the open internet offers an interactive login prompt to anyone who finds it.

Why exposed RDP is dangerous

Three attack paths converge on port 3389. Password guessing and credential stuffing against a login that often lacks lockout or multi-factor protection. Reuse of credentials harvested elsewhere. And exploitation of protocol vulnerabilities — BlueKeep (CVE-2019-0708) being the best-known pre-authentication example, which was serious enough to prompt patches for out-of-support Windows versions.

Success gives an interactive session on a Windows host rather than a shell on a peripheral service, which is why exposed RDP is a well-documented initial access route in ransomware incidents and appears in MITRE ATT&CK as a Remote Services technique.

Safer patterns

The general answer is not to publish 3389. Put remote access behind a VPN gateway or an identity-aware proxy, or use Microsoft’s Remote Desktop Gateway so that RDP is brokered over TLS after authentication. Where direct exposure is genuinely unavoidable, restrict by source address, enforce Network Level Authentication, require multi-factor authentication, and apply account lockout. Changing the port to something other than 3389 does not help much — port scanning and service fingerprinting find it regardless.

Exposed RDP is often not a decision at all: it is a firewall rule added for a supplier years ago, or a cloud instance launched with a permissive security group.

See SSH for the equivalent on Unix-like systems, and SMB and telnet for other services that should not face the internet. See also network segmentation and attack surface reduction.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.