Voicemod

Voicemod

Real-time voice changer that works with any application and comes equipped with an extensive collection of voices and ambient effects

FULL VERSION + CRACK
Flvto Youtube Downloader

Flvto Youtube Downloader

With this simple and intuitive application, you can swiftly download all your favorite online videos to your computer, in just a couple of moves

FULL VERSION + CRACK
Logic Pro X

Logic Pro X

A fully-featured recoding studio that provides a complete set of tools for musicians who need to write, record, edit and mix music

FULL VERSION + CRACK
Internet Download Manager (IDM)

Internet Download Manager (IDM)

Push your Internet connection to the limits and cleverly organize or synchronize download processes with this powerful application

FULL VERSION + CRACK
iMyFone LockWiper

iMyFone LockWiper

Helps you bypass the iPhone passcode in case you forgot it and the device became unusable or you have to wait for a long time before attempting to unlock it again

FULL VERSION + CRACK

IT News

Aug 23
JavaScript, database support also get nods
Aug 22
Microsoft on Tuesday launched a Beta build of its browser for all supported editions of Windows, including 7 and 10, and macOS.
Aug 22
Big Switch's new products include a version of its Big Cloud Fabric (BCF) for Amazon Web Services virtual private cloud (VPC) management, adding support for Global VPCs (G-VPCs), and a cloud-based version of its Multi-Cloud Director...
Aug 22
The WebKit team has unveiled a new Tracking Prevention Policy that could help bolster privacy for users of Apple's Safari browser.
Aug 22
With citizens' PII at risk, some federal agencies like the IRS are moving away from knowledge-based verification. It's time for them all to follow suit.
Aug 21
Better performance, increased Java community engagement are the goals
Aug 20
Microsoft has made it clear that it wants companies to embrace Windows 10 Enterprise, leaving the lesser Pro version in the dust. Gartner analyst Stephen Kleynhans sees no reason that will change.

Categories

Microsoft urges Windows customers to patch wormable RDP flaw

Microsoft has fixed a critical vulnerability in some versions of Windows that can be exploited to create a powerful worm. The company even took the unusual step of releasing patches for Windows XP and Windows Server 2003, which haven't been supported in years, because it believes the threat to be very high.

The vulnerability, tracked as CVE-2019-0708, is located in Remote Desktop Services, formerly known as Terminal Services. This component handles connections over the Remote Desktop Protocol (RDP), a widely used protocol for remotely managing Windows systems on corporate networks.

What makes the vulnerability so dangerous is that it can be exploited remotely with no authentication or user interaction by simply sending a maliciously crafted RDP request to a vulnerable system. A successful attack can result in malicious code being executed on the system with full user rights, giving attackers the ability to install programs, modify or delete user data and even to create new accounts.

"In other words, the vulnerability is 'wormable', meaning that any future malware that exploits this vulnerability could propagate from vulnerable computer to vulnerable computer in a similar way as the WannaCry malware spread across the globe in 2017," Simon Pope, director of Incident Response at the Microsoft Security Response Center, said in a blog post. "While we have observed no exploitation of this vulnerability, it is highly likely that malicious actors will write an exploit for this vulnerability and incorporate it into their malware."

WannaCry did not exploit a vulnerability in RDP, but in Microsoft's implementation of SMB, a file sharing and authentication protocol that's used on all Windows networks and is enabled by default. While the attacks are different, Pope's analogy to WannaCry is based on the ease of exploitation -- remotely with no authentication -- and the popularity of both protocols.

RDP has been a popular infection vector for malware threats in the past, particularly for ransomware, cryptominers and point-of-sale memory scrapers. Attackers typically steal or bruteforce RDP credentials in order to gain access to systems.

Earlier this year, the FBI shut down an underground marketplace called xDedic that was used to sell RDP access to tens of thousands of compromised servers over the course of several years. The prices ranged from $6 to $10,000, based on a server's geographic location, operating system and other criteria. This new RDP vulnerability would provide attackers with such access for free to an even larger number of servers and systems.

Legacy Windows systems at risk

The vulnerability affects Remote Desktop Services in Windows 7, Windows Server 2008 R2 and Windows Server 2008, as well as in legacy Windows versions that have reached end of life. In addition to supported Windows versions, Microsoft decided to release security updates for Windows XP, Windows XP Embedded and Windows Server 2003, probably because these Windows versions are still widely used in legacy environments and on specialized equipment like ATMs, medical devices, self-service kiosks, point-of-sale terminals and more.

It's worth noting that the destructive WannaCry and NotPetya ransomware worms both exploited known vulnerabilities that had patches available when they hit, yet the attacks still disrupted normal operations in hospitals, production plants, ports, railways and many businesses around the world. That's because many legacy systems and devices are used to run critical processes, so even when patches are available, their owners might not apply them for a very long time because they can't afford the downtime.

In the absence of immediate patching, the owners of such systems should take a more defense-in-depth approach by putting these devices on isolated network segments, disabling services that are not needed and using secure VPN solutions to access them remotely.

"Disable Remote Desktop Services if they are not required," Microsoft said in its advisory. "If you no longer need these services on your system, consider disabling them as a security best practice. Disabling unused and unneeded services helps reduce your exposure to security vulnerabilities."

Microsoft also suggests two workarounds for blocking attacks that might target this RDP vulnerability: Enabling Network Level Authentication (NLA) on systems running supported editions of Windows 7, Windows Server 2008, and Windows Server 2008 R2; and blocking TCP port 3389 at the enterprise perimeter firewall to prevent attacks that originate from the internet.

This story, "Microsoft urges Windows customers to patch wormable RDP flaw" was originally published by CSO.