July 14, 2017 By Mark Samuels 2 min read

Two security vulnerabilities have been uncovered in Microsoft Windows, and they could put businesses at risk of credential forwarding and password cracking.

Security vendor Preempt discovered the bugs in the security protocols of Microsoft Windows NT LAN Manager (NTLM). Researchers at the firm suggested that the vulnerabilities were caused by improper handling of NTLM by system protocols.

Microsoft addressed the vulnerabilities in its recent Patch Tuesday update. IT and network managers should pay attention to these updates and consider other precautionary steps, including avoiding the use of NTML altogether.

Breaking Down the Vulnerabilities

According to ZDNet, the first vulnerability, known as CVE-2017-8563, highlights how Lightweight Directory Access Protocol (LDAP) is not protected from NTLM relay. A security flaw in the protocol means that it does not always protect the user from credential forwarding.

An attacker with system privileges can use an incoming NTML session to perform LDAP operations on behalf of the user. Attackers can subsequently establish a domain admin account and take control of the network.

The second vulnerability covers remote desktop protocol (RDP) Restricted-Admin Mode, which enables individuals to connect to a remote machine without entering a password. Attackers could potentially exploit this mode to perform password cracking or credential relaying attacks with NTLM.

These two vulnerabilities are important because an attacker could potentially create new domain administrator accounts despite the use of network controls, wrote researcher Yaron Zinar in a post on Preempt’s blog.

Relay attacks, which rely on a user connecting to an infected computer, have been known to exist for more than 10 years, Bleeping Computer reported. The computer is usually infected with malware, takes NTLM credentials, and then relays them to a third party or performs malicious actions without the user’s knowledge.

Microsoft acknowledged both issues and released a fix for CVE-2017-8563 in its security update for July. The technology giant claimed that the second concern is a known issue and network configuration can help keep users safe from malicious NTLM relays.

Managing Security Vulnerabilities

Preempt noted that using NTLM puts businesses at risk of credential forwarding and password cracking. In fact, Zinar advised IT managers to avoid using NTLM in their networks, if possible.

For firms that continue to use it, Zinar suggested several precautionary steps, such as installing the CVE-2017-8563 patch on all domain controllers, monitoring NTLM traffic across the network and withholding domain admin privileges from help desk personnel.

Experts recognize that managing security vulnerabilities can be tough, especially when the risk of infection is high and technology budgets are constrained. Precautionary steps, such as those outlined by Zinar above, can help. Other best practice techniques include vulnerability scanning through analytics technologies. Above all else, IT and network managers should play close attention to updates from technology partners.

More from

When ransomware kills: Attacks on healthcare facilities

4 min read - As ransomware attacks continue to escalate, their toll is often measured in data loss and financial strain. But what about the loss of human life? Nowhere is the ransomware threat more acute than in the healthcare sector, where patients’ lives are literally on the line.Since 2015, there has been a staggering increase in ransomware attacks on healthcare facilities. And the impacts are severe: Diverted emergency services, delayed critical treatments and even fatalities. Meanwhile, the pledge some ransomware groups made during…

AI and cloud vulnerabilities aren’t the only threats facing CISOs today

6 min read - With cloud infrastructure and, more recently, artificial intelligence (AI) systems becoming prime targets for attackers, security leaders are laser-focused on defending these high-profile areas. They’re right to do so, too, as cyber criminals turn to new and emerging technologies to launch and scale ever more sophisticated attacks.However, this heightened attention to emerging threats makes it easy to overlook traditional attack vectors, such as human-driven social engineering and vulnerabilities in physical security.As adversaries exploit an ever-wider range of potential entry points…

4 trends in software supply chain security

4 min read - Some of the biggest and most infamous cyberattacks of the past decade were caused by a security breakdown in the software supply chain. SolarWinds was probably the most well-known, but it was not alone. Incidents against companies like Equifax and tools like MOVEit also wreaked havoc for organizations and customers whose sensitive information was compromised.Expect to see more software supply chain attacks moving forward. According to ReversingLabs' The State of Software Supply Chain Security 2024 study, attacks against the software…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today