INFOCON Yellow - Microsoft RDP - MS12-020
As we feared the MS12-020 bulletin from last black Tuesday caused a race for finding an exploit.
The last few evolutions in that process cause our worries to increase significantly. In order to help raise awareness and call administrators to action, we're raising our INFOCON to YELLOW for 24 hours.
Some history:
- Luigi Auriemma found a problem on May 16th, 2011.
- Microsoft was warned on August 24th, 2011 working with TippingPoint's Zero Day Initiative
- Microsoft released bulletin MS12-020 on March 13th, 2012, crediting "Luigi Auriemma, working with TippingPoint's Zero Day Initiative, for reporting an issue described in MS12-020"
- Luigi Auriemma released his work on March 16th, 2012
Luigi wrote today: "now that my proof-of-concept is out (yeah rdpclient.exe is the poc written by Microsoft in November 2011 using the example packet I sent to ZDI) I have decided to release my original advisory and proof-of-concept packet written the 16 May 2011... full-disclosure as usual :)" and he released his analysis and exploit of the vulnerability.
This is expected to speed up the efforts of the bad guys significantly and gives those having exposed RDP services very little time to fix before it will get exploited somehow.
The clock is ticking, please consider:
- block off RDP from all sources but those you absolutely need
- install the Microsoft patch
--
Swa Frantzen -- Section 66
Comments
Oops.
Kevin
Mar 16th 2012
1 decade ago
baillard
Mar 16th 2012
1 decade ago
The path to the setting is computer configuration:policies:administrative templates:windows components:remote desktop services:remote desktop session host:security:require user authentication for remote connections by using.....
Takes effect without a reboot, and obviously doesn't help with XP/2003 server machines, but it's often quicker to deploy a GPO than it is to deploy a patch and wait for an outage window to reboot, or rely on a user rebooting.
Ric
Mar 16th 2012
1 decade ago
There are also quite a few recent stories on Google News: https://www.google.com/search?q=MS12-020&tbm=nws
@baillard: I did receive an SMS at 10:15 CDT.
James W
Mar 16th 2012
1 decade ago
Also there wasn't a tweet to "SANS ISC Fast" about the INFOCONN status change, 2000+ follower's may still not know :-/
FTWMike
Mar 16th 2012
1 decade ago
James W
Mar 16th 2012
1 decade ago