Skip to main content

Port Details

Port
3389
Transport
TCP / UDP
Service
RDP
IANA service name
ms-wbt-server
Range
User port (1024-49151)

Security Exposure

Shadowserver reports internet-accessible RDP as high severity, noting that misconfigured RDP can give attackers desktop access and that its TLS certificate often reveals the host name. CISA's BlueKeep advisory (CVE-2019-0708) describes a pre-authentication remote code execution flaw in Remote Desktop Services and recommends blocking TCP 3389 at the enterprise perimeter. Exposed RDP also invites password guessing against Windows accounts.

Hardening

  • +Block TCP 3389 at the enterprise perimeter firewall, as CISA advises in its BlueKeep guidance.
  • +Require Network Level Authentication so users authenticate before a session is created.
  • +Install Windows security updates promptly and disable Remote Desktop on systems that do not need it.
  • +Limit the accounts permitted to log on through Remote Desktop to the users who need it.

Monitoring

Monitor Security event 4625 (failed logon) and 4624 (successful logon) with logon type 10 (RemoteInteractive), which Windows records for Remote Desktop logons. Alert on bursts of failures or logons from unusual sources.

RDP Vulnerabilities

2 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-21533
Windows Remote Desktop Services Elevation of Privilege Vulnerability
Microsoft7.84.2%KEV2026-02-10
CVE-2019-0708
Microsoft Remote Desktop Services Remote Code Execution Vulnerability
Microsoft9.8100.0%KEV2019-05-16

Tools for Auditing and Monitoring RDP

Sysmon

Free
SIEM Tools

Windows Sysinternals service that logs detailed process, network, and file activity to the event log.

LicenseProprietary
PlatformWindows

Chainsaw

Open Source
Digital Forensics

Applies Sigma and custom rules to search Windows event logs, MFT records, registry hives, and SRUM data for rapid incident triage.

LicenseGPL-3.0-only
PlatformLinux, Windows, macOS

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Frequently Asked Questions

Is RDP port 3389 TCP or UDP?→

Both. Microsoft lists Remote Desktop Services on TCP 3389 and UDP 3389.

Should port 3389 be open to the internet?→

No. CISA recommends blocking TCP 3389 at the enterprise perimeter firewall, and Shadowserver treats internet-accessible RDP as high severity.

Does changing the RDP port from 3389 improve security?→

Microsoft documents how to change the listening port. A different port does not replace the mitigations CISA lists for RDP: installing patches, enabling Network Level Authentication and blocking the RDP port at the perimeter firewall.

Which vulnerabilities affect the service on port 3389?→

This database lists 2 CVEs related to RDP, 2 of them confirmed as exploited by CISA. Examples: CVE-2026-21533, CVE-2019-0708.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 3389 is not guaranteed to be RDP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).