Newsletters
Technology, Discovery & Innovation NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
This ad will display for the next 20 seconds. Click for more information, or
Home Computing Digital Life Discovery Space More Topics...
APC Free White Paper
Optimize your network investment &
Enter to win a Samsung Galaxy Note

www.apc.com
Computing
Average Rating:
Rate this article:  
Patch Tuesday Focus Is on Critical RDP Flaw
Patch Tuesday Focus Is on Critical RDP Flaw

By Jennifer LeClaire
March 14, 2012 10:30AM

Bookmark and Share
"This brings back a scary, old buzzword though, it's 'wormable.' It's a scary word, but MS12-020 makes it completely possible," said security researcher Tyler Reguly of Patch Tuesday fixes. "This might be the month to throw the patch rulebook out the window and install this patch faster than your enterprise patch cycle normally allows."
 



Microsoft on Tuesday released six comprehensive security updates as part of its regular monthly cycle to help protect its customers from potential cyber-attacks. All security researchers agree that MS12-020 is the key focus.

Microsoft also issued a "Fix-it" this month that lets IT admins enable Network Level Authentication, which mitigates against certain potential exploit vectors. IT admins can use the Fix-it for added protection as they evaluate MS12-020, which is susceptible to pre-authentication exploit on systems running Remote Desktop Protocol without enabling NLA.

"We understand that our customers need time to evaluate and test all bulletins before applying them. To provide for a bit of scheduling flexibility, we're offering a one-click, no-reboot Fix-it that enables Network-Level Authentication, an effective mitigation for this issue," Angela Gunn of Microsoft's Trustworthy Computing group wrote in a blog post. Gunn said the Fix-it applies to Vista, Server 2008, Windows 7 and Server 2008R2 systems.

Exploits Coming Soon

RDP is a popular method for controlling remote Windows machines, however it is not active by default on standard Windows installations, said Wolfgang Kandek, CTO of Qualys. It needs to be configured and started by the system's owner, which then makes the vulnerability accessible.

"Consequently we expect that only a relatively small percentage of machines will have RDP up and running. The vulnerability itself is accessible through the network, does not require authentication and allows code execution on the targeted machine, a highly prized combination by attackers," Kandek said. "Microsoft has rated its exploitability index as 1, meaning that they expect working exploits to be out in fewer than 30 days."

RDP Recommendations

Kandek is making some clear recommendations for the RDP vulnerability. First, within the week apply the patch on Windows machines that are running the Internet-facing RDP service. According to Kandek, IT admins can scan for port 3389 on the perimeter if there is no updated map.

The patch requires a reboot to become active. IT admins that cannot apply the patch or reboot machines, Kandek said, can configure the firewalls on the machines so that only trusted IPs can access port 3389. He also recommended activating the NLA protocol, which does not have this vulnerability.

"Within the month patch the rest of your systems -- both external and internal," Kandek said. "While the main attack vector is directly through the Internet, it is likely that malware will be equipped with the exploit for the RDP vulnerability, and that it will be used for internal malware propagation."

An Unpleasant Flashback

Tyler Reguly, technical manager of security research and development at nCircle, said Tuesday was a flashback of the bad old Patch Tuesdays. Remote, unauthenticated vulnerability attacks are becoming a rarity these days, with end user and client software being the attack vector of choice recently.

"This brings back a scary, old buzzword though, it's 'wormable.' It's a scary word, but MS12-020 makes it completely possible," Reguly said. "This might be the month to throw the patch rulebook out the window and install this patch faster than your enterprise patch cycle normally allows. It's critical that enterprises apply the MS12-020 patch as quickly as possible."
 

Tell Us What You Think
Comment:

Name:

Advertisement
Free Gartner Report:
Drive innovation & collaboration
with the "Everyone's IT" approach.

View the research report
.



APC has an established a reputation for solid products that virtually pay for themselves upon installation. Who has time to spend worrying about system downtime? APC makes it easy for you to focus on business growth instead of business downtime with reliable data center systems and IT solutions. Learn more here.


 Computing
1.   Tor Internet Privacy Service Breached
2.   Oracle Updates Database, Linux Products
3.   AMD Announces ARM Server Chips
4.   Canada Says China Hacked Gov't
5.   MacBook Pros Get Update, Price Cut


advertisement
Amazon Intros Zocalo Storage Service
Online storage and sharing for business.
Average Rating:
Tor Internet Privacy Service Breached
Users should assume they're affected.
Average Rating:
AMD Announces ARM Server Chips
Chipmaker has Intel in its sights.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Tor Internet Privacy Service Warns Users It Was Breached
You may never have heard of the Tor Project, but the Internet privacy service is making headlines. Tor’s devs say users might be victims of an attack launched against the project earlier this year.
 
Canadian Government Charges China With Cyberattack
The government of Canada is not happy with China. Canadian officials have accused "a highly sophisticated Chinese state-sponsored actor" of launching a cyberattack on its National Research Council.
 
Researchers Working To Fix Tor Security Exploit
Developers for the Tor privacy browser are scrambling to fix a bug revealed Monday that researchers say could allow hackers, or government surveillance agencies, to track users online.
 

Enterprise Hardware Spotlight
Apple Updates MacBook Pros, Cuts Prices Up to $100
The popular MacBook Pro laptop line just got an update and a price cut of as much as $100. The MacBook Pro with Retina display now includes faster processors and double the memory.
 
Dell, BlackBerry Not Sweating Apple-IBM Alliance
IBM's recent move to partner with Apple to sell iPhones and iPads loaded with corporate applications has excited investors in both companies, but two rivals say they are unperturbed for now.
 
Watson Gets His First Customer Service Gig
Since appearing on Jeopardy, IBM's Watson supercomputer has been making a living using his super-intelligent knowledge base for business verticals. Now, Watson's been hired for his first customer service job.
 

Mobile Technology Spotlight
Virgin Mobile Offers Custom Smartphone Plans
As the wireless carrier wars continue heating up, Virgin Mobile just threw the customization coal onto the fire. The firm has debuted a no-annual-contract plan with rates based on individual use.
 
Collaboration Provider Asana Revamps Mobile App
Asana, a collaboration software provider started by a Facebook founder, is now out with a rebuilt native iOS mobile app. It replaces one that even the company admits was not up to par.
 
Facebook: You Will Use Messenger, and You Will Like It
Starting this week, Facebook users with Android and iOS phones will be forced to use the separate Messenger app to send Facebook messages. Pending messages will still be visible in the main app.
 

Navigation
Sci-Tech Today
Home/Top News | Computing | Digital Life | Discovery | Space | Innovation | Health | Science News
Environment
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.