Saturday, March 2, 2019

Google suggested Upgrade to Windows 10 to Fix Windows 7 Zero-Day Bug (CVE-2019-5786)

Google advise users of Windows 7 to give it up and move to Microsoft’s latest operating system if they want to keep systems safe from a zero-day vulnerability exploited in the wild.
To remediate the Chrome vulnerability (CVE-2019-5786), Google released an update for all Chrome platforms on March 1; this update was pushed through Chrome auto-update. Google encourage users to verify that Chrome auto-update has already updated Chrome to 72.0.3626.121 or later.
Google suggested Upgrade to Windows 10 to Fix Windows 7 Zero-Day Bug (CVE-2019-5786)

Bug affects Windows win32k.sys kernel driver on Microsoft windows  and leads to privilege escalation on Windows 7. 

Windows win32k.sys kernel driver that can be used as a security sandbox escape. The vulnerability is a NULL pointer dereference in win32k!MNGetpItemFromIndexwhen NtUserMNDragOver() system call is called under specific circumstances.
Google strongly believe this vulnerability may only be exploitable on Windows 7 due to recent exploit mitigations added in newer versions of Windows. To date, Google have only observed active exploitation against Windows 7 32-bit systems.
Google reported it to Microsoft. Also in compliance with Google policy, Google publicly disclosing its existence, because it is a serious vulnerability in Windows that Google know was being actively exploited in targeted attacks. The unpatched Windows vulnerability can still be used to elevate privileges or combined with another browser vulnerability to evade security sandboxes. Microsoft have told Google they are working on a fix.
As mitigation advice for this vulnerability users should consider upgrading to Windows 10 if they are still running an older version of Windows, and to apply Windows patches from Microsoft when they become available. 



Share:

Wednesday, March 14, 2018

Dangerous CredSSP Vulnerability opens door into corporate servers

Dangerous CredSSP Vulnerability opens door into corporate servers

A critical vulnerability in the Credential Security Support Provider protocol (CredSSP), introduced in Windows Vista and used in all Windows versions since then, can be exploited by MitM attackers to run code remotely on previously uninfected machines and servers in the attacked network
Dangerous CredSSP Vulnerability opens door into corporate servers

In March Patch Tuesday, Microsoft released a patch for CVE-2018-0886, a vulnerability discovered by Preempt researchers. The vulnerability consists of a logical flaw in Credential Security Support Provider protocol (CredSSP) which is used by RDP (Remote Desktop Protocol) and Windows Remote Management (WinRM) that takes care of securely forwarding credentials to target servers. The vulnerability can be exploited by attackers by employing a man-in-the-middle attack to achieve the ability to run code remotely on previously not infected machines in the attacked network. The vulnerability, in many real-world scenarios where victim network has vulnerable network equipment, could result in an attacker gaining the ability to move laterally in the victim’s network and even infect domain controller with malicious software.

The vulnerability is a logical one and affects all Windows versions to date. In terms of the  vastness of this issue, we can note that RDP is the most popular application to perform remote logins. To further highlight this, in Preempt internal research we found that almost all enterprise customers are using RDP, making them vulnerable to this issue.

CredSSP Vulnerability Video




"This could leave enterprises vulnerable to a variety of threats from attackers including lateral movement and infection on critical servers or domain controllers."


Share:

Popular Posts