Skip to content

IT Hardware Asset Management and Microsoft's "New WannaCry" Security Threat

When Microsoft patched a wormable Remote Desktop flaw serious enough to warrant emergency updates for Windows XP, the hard part was not the patch. It was working out which machines you owned that needed it. That is a hardware asset management problem, and it has not gone away.

In May 2019 Microsoft published a fix for a Remote Desktop Services vulnerability serious enough that it also shipped emergency updates for operating systems it had stopped supporting years earlier. Windows XP and Windows Server 2003 both got a patch. That does not happen often, and when it does it is worth paying attention.

The flaw was CVE-2019-0708, later given the name BlueKeep. It allowed remote code execution over RDP with no authentication and no user interaction — the attacker did not need anyone to click anything. Microsoft rated it critical and warned it was wormable, meaning a working exploit could spread from machine to machine on its own. That is precisely the property that let WannaCry cross the planet in 2017, which is why the comparison was made at the time.

The affected versions were Windows XP through Windows 7, and Windows Server 2003 through Server 2008 R2.

The patch was never the hard part

Microsoft did the difficult engineering. The update existed, it was free, and it was available to everyone including organisations running unsupported operating systems.

What organisations could not do at speed was answer a much more basic question: which machines do we own that are exposed?

That question is not a security question. It is an IT hardware asset management question, and it is the one that determines how long you spend at risk. You cannot patch a device you do not know about. You cannot report on your remaining exposure if your inventory is a spreadsheet that was accurate last quarter. And you cannot tell a board that the risk is closed if the number you are quoting is an estimate.

Every incident of this shape follows the same sequence:

  1. Find every device, including the ones nobody has recorded.
  2. Establish the operating system, build and update level of each one.
  3. Work out which are missing the specific update.
  4. Distribute it.
  5. Prove the number remaining is zero, and keep proving it.

Steps one and two are where organisations lose days. Steps three to five are mechanical once you have them.

Finding the machines

CerteroX ITAM answers step one with ten discovery methods that all land in a single schema, so there is no reconciliation exercise between them:

  • Network Discovery across NetBIOS, SNMP and ICMP. It sweeps a class-C subnet in under five seconds and probes port 22, so you find machines before you own them in any management tool — including the ones no agent has ever reached.
  • The native inventory agent, which covers six operating system families: Windows, macOS, Linux, IBM AIX, HP-UX and Oracle Solaris. Same inventory cycle, same schema on all six.
  • Agentless and command-line inventory (csinvcli) for locked-down environments where an agent is not permitted, and standalone inventory for air-gapped and offline systems.
  • Active Directory import of computers, users, groups, sites and subnets.
  • Duplicate system detection and stale device archiving, so the count you report is a count of real machines rather than an accumulation of ghosts.

The last one matters more than it sounds during an incident. A device list inflated by duplicates and decommissioned hardware produces a remediation figure that never reaches zero, and nobody can tell whether the residue is a reporting artefact or a genuine gap.

Establishing update level, and closing the gap

Once the machines are known, CerteroX ITAM reports operating system, build and patch level down to the KB identifier, so “which devices are missing this specific update” is a query rather than a project.

Remediation runs from the same console:

  • WSUS-integrated patch management, including downstream server support, to approve and push the update.
  • Software distribution for MSI, EXE and Click-to-Run packages, where the fix is not a Windows update.
  • The SCCM interface, if SCCM is already your distribution mechanism — CerteroX can import and drive SCCM applications, packages and jobs rather than competing with them.
  • Mobile device management for iOS and Android, including Apple DEP.

And because CerteroX is delivered as SaaS, there is no server procurement cycle between deciding you need visibility and having it. Certero’s founder and CEO, John Lunt, made this point at the time: an organisation worried about a live vulnerability does not have weeks to stand up infrastructure before it can start looking. An on-premises or hybrid deployment remains available where that is the requirement.

Making it stick after the incident

The part of this that has changed most since 2019 is what happens next.

Patching a specific CVE is a one-off. Not being caught out by the next one is a standing control, and CerteroX ITAM expresses those as Governance Policies — compliance as code, built on a reusable filter builder. A policy is a condition evaluated continuously across everything discovered: BitLocker enabled, Defender running, Azure VM tag hygiene, and whatever else your security team considers non-negotiable. Policy definitions export and import as JSON, so a control that works in one environment can be moved to another rather than rebuilt.

That turns “are we exposed?” from a fire drill into a dashboard, with threshold alerts when the answer changes.

The 2026 version of the same problem

The specific flaw described here is long patched. The pattern is not.

Windows 10 reached end of support on 14 October 2025. Every device still running it is in the same position the Windows 7 and Server 2008 R2 machines were in when BlueKeep landed: functional, in daily use, and no longer receiving security updates by default. The organisations that handled that deadline well were the ones who could produce an accurate, current count of affected devices — by location, by owner, by hardware model, and split by which of them could actually take the upgrade.

CerteroX ITAM does that specific job with Windows 11 upgrade orchestration against the hardware inventory it already holds, so eligibility and remediation run off one record rather than two.

The lesson from 2019 holds. When the next wormable vulnerability is published, the organisations that close it fastest will not be the ones with the best patching tool. They will be the ones who already knew what they owned.

Related reading

Other posts covering the same ground.

  • Windows 11 migration: why it matters

    Windows 10 support ended in October 2025. If you are still finishing the migration — or paying for Extended Security Updates while you do — these are the questions to settle and a readiness check to score yourself against.

    • ITAM
    • Governance
    • Security
    8 min
  • Manage Android Devices and iOS Across Your IT Ecosystem

    Mobile device management works properly when phones and tablets sit in the same inventory as everything else you own. Here is what CerteroX ITAM does with enrolled iOS and Android devices, and why the single record matters.

    • ITAM
    • Governance
    • Security
    6 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.