Chinese firm leaked RDP exploit code

Powered by SC Magazine
 

Microsoft boots security firm from partner program.

Microsoft has blamed a Chinese security firm for leaking Remote Desktop Protocol (RDP) exploit code that was patched in March.

Hangzhou DPTech Technologies Co, a specialist in firewalls and intrusion prevention systems, breached its non-disclosure contract with the Microsoft Active Protections Program (MAPP) by releasing the code.

It was booted from Microsoft's vulnerability-sharing program last week.

Under MAPP, Microsoft shares vulnerability details with approved software security providers prior to its monthly fixes being released to allow security firms to immediately protect their customers once the patches are delivered.

Specifically MAPP provides its partners with a comprehensive explanation of the vulnerability, a blueprint to trigger the flaw, information on how to detect the bug and a proof-of-concept file.

The vulnerability in question, a "wormable" weakness in the Windows RDP, was discovered in May 2011 by researcher Luigi Auriemma, who reported his find to TippingPoint's Zero Day Initiative (ZDI) bug bounty service.

It was handed in August to Microsoft to develop a fix.

In March, Microsoft released a patch that came with a warning that the software giant expected to see a code-execution exploit released within 30 days.

It took about two days for a proof-of concept (PoC) to appear on a Chinese hacker site. No known remote exploit has been released.

Upon investigation, Auriemma discovered many similarities between the published PoC and the one that he sent ZDI so the service could test the vulnerability.

As further proof, the posted code appeared modelled after the PoC that Microsoft developed in November for internal tests, and which, he concluded, was likely distributed to partners as part of the MAPP.

"[The PoC published on the Chinese site] contains some debugging strings like 'MSRC11678' which is a clear reference to the Microsoft Security Response Center," Auriemma said.

Based on the evidence, Auriemma determined that those responsible for creating the publicly available PoC were the beneficiaries of a leak.

Microsoft said it would tighten the security controls around MAPP, though it would not elaborate on its plans.

MAPP team manager Maarten Van Horenbeeck said Microsoft took careful steps to ensure incidents like this rarely occurred.

"We recognise that there is the potential for vulnerability information to be misused," he said.

"In order to limit this as much as possible, we have strong non-disclosure agreements (NDA) with our partners. Microsoft takes breaches of its NDAs very seriously. In addition, we make sure to only release data shortly in advance of the security update.

"Today, we send MAPP data to our partners just as far in advance as they need to get that work done."

A Microsoft spokeswoman could not immediately be reached for comment. An email sent to DPTech for comment was not immediately returned.

This article originally appeared at scmagazineus.com

Copyright © SC Magazine, US edition


Chinese firm leaked RDP exploit code
 
 
 
Top Stories
Coalition's NBN cost-benefit study finds in favour of MTM
FTTP costs too much, would take too long.
 
Who'd have picked a BlackBerry for the Internet of Things?
[Blog] BlackBerry has a more secure future in the physical world.
 
Will Nutanix be outflanked before reaching IPO?
VMware muscles in on storage startup in hyper-converged infrastructure.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Looking for storage? Seagate has five new small business NAS devices
Aug 22, 2014
Seagate has announced a new portfolio of Networked Attached Storage (NAS) solutions specifically ...
Run a small business in western Sydney?
Aug 15, 2014
This event might be of interest if you're looking to meet other people with a similar interest ...
Buying a tablet? Microsoft's Surface Pro 3 goes on sale this month
Aug 8, 2014
Microsoft has announced its Surface Pro 3 will go on sale in Australia on 28 August from ...
Apple's top MacBook Pro with Retina is now cheaper
Aug 1, 2014
Apple has updated its MacBook Pro range with faster processors and new pricing, including ...
Pass on carbon tax savings, warns ACCC
Jul 24, 2014
The ACCC is warning businesses that supply "regulated goods" to pass on any cost savings ...
Latest Comments
Polls
Which is the most prevalent cyber attack method your organisation faces?




   |   View results
Phishing and social engineering
  68%
 
Advanced persistent threats
  3%
 
Unpatched or unsupported software vulnerabilities
  11%
 
Denial of service attacks
  6%
 
Insider threats
  11%
TOTAL VOTES: 603

Vote