Law Firm CISO's Weak Password and Unpatched BlueKeep Expose Firm to Risk
A penetration test at a national law firm revealed critical security failures, including unpatched Windows machines vulnerable to BlueKeep and the CISO's easily compromised password.

A recent penetration test at a national law firm uncovered significant security vulnerabilities, including the continued exploitation of the BlueKeep remote code execution flaw on unpatched Windows systems. The assessment, conducted by security professional Joe Brinkley, highlighted a stark contrast between the firm's previous investments in security software and its ongoing failure to address fundamental patching requirements.
Brinkley, who had previously audited the same firm a year prior, noted that despite a substantial investment of approximately half a million dollars in security software and remediation efforts following his initial findings, the firm had neglected to patch its Windows machines against BlueKeep. This critical vulnerability, first disclosed and patched in 2019, affects numerous Windows versions, including Windows 2000, Server 2008 R2, and Windows 7, with related DejaBlue flaws impacting Windows 10. The vulnerability leverages a flaw in the Remote Desktop Protocol (RDP), allowing attackers to execute remote code and potentially spread malware wormably across networks.
The penetration test revealed that attackers could exploit BlueKeep to gain unauthorized access to the firm's systems. Once inside, Brinkley discovered that passwords were stored in plain text, making them trivial to extract. The firm had also employed an obscure naming convention for user accounts, using pseudonyms like "Yellow Banana" and "Red Apple" in an attempt to obscure administrative privileges, a tactic that proved ineffective.
During the assessment, Brinkley successfully obtained the password for the "Yellow Banana" account, which was "r3@lg00dp@$$w0rd" – a deliberately weak password with common substitutions for letters. This discovery was made public when Brinkley presented his findings to the firm's executives, including a screenshot of the password. The CISO, present at the presentation, reacted with surprise and dismay, inadvertently revealing that he was the user behind the "Yellow Banana" account and that he had considered the password to be secure.
This incident underscores a critical lapse in security hygiene at multiple levels within the law firm. The failure to patch a known, high-impact vulnerability like BlueKeep demonstrates a significant oversight in patch management processes. Furthermore, the use of weak, easily guessable passwords, even by the Chief Information Security Officer, highlights a profound lack of awareness regarding basic password security best practices.
The implications of these failures are severe. An unpatched BlueKeep vulnerability provides a direct pathway for attackers to compromise systems, potentially leading to data breaches, ransomware attacks, or complete network takeover. The presence of plain-text passwords exacerbates this risk, offering attackers a readily available list of credentials to escalate their access and move laterally within the network.
While the firm had invested heavily in security software, the penetration test revealed that such investments are insufficient without a robust foundation of fundamental security practices. The incident serves as a stark reminder that effective cybersecurity requires continuous vigilance, diligent patching, strong password policies, and comprehensive security awareness training for all employees, especially leadership.
Moving forward, the law firm must prioritize immediate patching of all vulnerable systems and implement stricter controls around password complexity, multi-factor authentication, and credential storage. The embarrassment faced by the CISO highlights the need for a cultural shift towards security-first thinking, ensuring that even the most basic security measures are consistently enforced.