The templates (on provision) actually do set up 3389. Unless that has very recently changed.
The first Virtual Machine deployed in an "IaaS Service" gets 3389 mapped to 3389. Only using the API can you prevent the endpoint from being created by default, or defining its port number. Any Virtual Machines in an "IaaS Service"beyond 1 get
an ephemeral port mapped to 3389 by default.
The machine is being exploited / hacked. Is it patch related, no. Simply opportunistic.
Folks just are not locking things tight enough. Or things are being deployed and played with without the extra measures put into place (that an IT department would impose).
Still. Better to learn about these things and how they are working as that feeds back into practice.
So for quick test environments that are not under the watch of IT or security folks. There is huge potential. A machine could be compromised simply as it is being secured, after provisioning - very quickly.
Brian Ehlert
http://ITProctology.blogspot.com
Learn. Apply. Repeat.
Disclaimer: Attempting change is of your own free will.