Port 3389: Remote Desktop Protocol
Remote Desktop listens on port 3389 by default, giving interactive remote access to Windows desktops and servers over RDP. Microsoft's port reference lists Remote Desktop Services on both TCP and UDP 3389. The listening port is stored in the registry and can be changed.
Port Details
Security Exposure
Shadowserver reports internet-accessible RDP as high severity, noting that misconfigured RDP can give attackers desktop access and that its TLS certificate often reveals the host name. CISA's BlueKeep advisory (CVE-2019-0708) describes a pre-authentication remote code execution flaw in Remote Desktop Services and recommends blocking TCP 3389 at the enterprise perimeter. Exposed RDP also invites password guessing against Windows accounts.
Hardening
- +Block TCP 3389 at the enterprise perimeter firewall, as CISA advises in its BlueKeep guidance.
- +Require Network Level Authentication so users authenticate before a session is created.
- +Install Windows security updates promptly and disable Remote Desktop on systems that do not need it.
- +Limit the accounts permitted to log on through Remote Desktop to the users who need it.
Monitoring
Monitor Security event 4625 (failed logon) and 4624 (successful logon) with logon type 10 (RemoteInteractive), which Windows records for Remote Desktop logons. Alert on bursts of failures or logons from unusual sources.
RDP Vulnerabilities
2 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-21533 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | Microsoft | 7.8 | 4.2% | KEV | 2026-02-10 |
| CVE-2019-0708 | Microsoft Remote Desktop Services Remote Code Execution Vulnerability | Microsoft | 9.8 | 100.0% | KEV | 2019-05-16 |
Tools for Auditing and Monitoring RDP
Sysmon
FreeWindows Sysinternals service that logs detailed process, network, and file activity to the event log.
Chainsaw
Open SourceApplies Sigma and custom rules to search Windows event logs, MFT records, registry hives, and SRUM data for rapid incident triage.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Related Tool Categories
Frequently Asked Questions
Is RDP port 3389 TCP or UDP?→
Both. Microsoft lists Remote Desktop Services on TCP 3389 and UDP 3389.
Should port 3389 be open to the internet?→
No. CISA recommends blocking TCP 3389 at the enterprise perimeter firewall, and Shadowserver treats internet-accessible RDP as high severity.
Does changing the RDP port from 3389 improve security?→
Microsoft documents how to change the listening port. A different port does not replace the mitigations CISA lists for RDP: installing patches, enabling Network Level Authentication and blocking the RDP port at the perimeter firewall.
Which vulnerabilities affect the service on port 3389?→
This database lists 2 CVEs related to RDP, 2 of them confirmed as exploited by CISA. Examples: CVE-2026-21533, CVE-2019-0708.
Sources
- IANA Service Name and Transport Protocol Port Number Registry: port 3389
- Microsoft Learn: Service overview and network port requirements for Windows
- Microsoft Learn: Change the listening port for Remote Desktop on your computer
- Microsoft Learn: Allow access to your PC with Remote Desktop (Network Level Authentication)
- CISA Advisory AA19-168A: Microsoft Operating Systems BlueKeep Vulnerability
- Shadowserver: Accessible RDP Report
- Microsoft Learn: 4625(F) An account failed to log on
- Microsoft Learn: 4624(S) An account was successfully logged on
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 3389 is not guaranteed to be RDP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).