Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
Critical Flaws Found in Windows NTLM Security Protocol – Patch Now
#1
[Image: wndows-security-update.png]

As part of this month's Patch Tuesday, Microsoft has released security patches for a serious privilege escalation vulnerability which affect all versions of its Windows operating system for enterprises released since 2007.

Researchers at behavioral firewall specialist Preempt discovered two zero-day vulnerabilities in Windows NTLM security protocols, both of which allow attackers to create a new domain administrator account and get control of the entire domain.

NT LAN Manager (NTLM) is an old authentication protocol used on networks that include systems running the Windows operating system and stand-alone systems.


Although NTLM was replaced by Kerberos in Windows 2000 that adds greater security to systems on a network, NTLM is still supported by Microsoft and continues to be used widely.

The first vulnerability involves unprotected Lightweight Directory Access Protocol (LDAP) from NTLM relay, and the second impact Remote Desktop Protocol (RDP) Restricted-Admin mode.

LDAP fails to adequately protect against NTLM relay attacks, even when it has built-in LDAP signing the defensive measure, which only protects from man-in-the-middle (MitM) attacks and not from credential forwarding at all.

The vulnerability could allow an attacker with SYSTEM privileges on a target system to use incoming NTLM sessions and perform the LDAP operations, like updating domain objects, on behalf of the NTLM user.

Full Article
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  I review security software for a living and I just found a new way to stop online sca mrtrout 0 890 01-06-2024 , 04:30 AM
Last Post: mrtrout
  Atlassian reveals critical flaws in almost everything it makes and touches mrtrout 0 600 07-21-2022 , 07:56 PM
Last Post: mrtrout
  Microsoft November 2021 Patch Tuesday fixes 6 zero-days, 55 flaws mrtrout 0 528 11-09-2021 , 10:20 PM
Last Post: mrtrout
  Critical Vulnerabilities Found in Custom TCP/IP Stack mrtrout 0 680 08-06-2021 , 03:37 AM
Last Post: mrtrout
  F5 urges customers to patch 4 critical BIG-IP pre-auth RCE bugs Bjyda 0 902 03-11-2021 , 10:48 PM
Last Post: Bjyda

Forum Jump:


Users browsing this thread: 1 Guest(s)