iTnews

Microsoft patches critical JASBUG Windows flaw

By Juha Saarinen on Feb 11, 2015 6:25AM
Microsoft patches critical JASBUG Windows flaw

Vulnerability affects millions of Active Directory-connected systems.

Microsoft has issued an urgent security advisory for a critical flaw in Windows that allows attackers to remotely gain full control of user systems.

Named "JASBUG", the vulnerability affects all computers and devices that are members of corporate Active Directories.

The flaw was discovered by security firm JAS Global Advisers, which reported the vulnerability to Microsoft in January last year. 

Although JAS said Microsoft immediately understood the seriousness of the vulnerability, fixing the problem was more difficult because it was caused by a design problem introduced in Windows 15 years ago, rather than simply a software bug.

The design flaw means devices on corporate networks don't adequately verify the authenticity of the Active Directory server they connect to. 

In order to remedy the flaw, Microsoft was forced to re-engineer core components of Windows, to add several new features.

This meant extensive testing to ensure backwards compatibility, supported configurations, and new documentation to describe the changes was required, a process that took Microsoft over a year.

Microsoft rates the vulnerability in AD Group Policy as critical, and said it allows remote code execution with complete control of user systems.

In order to exploit the vulnerability, users with domain-configured Windows systems only need to be lured to connect to networks under attackers' control.

Once connected, attackers can install software, view, change and delete data as well as create new accounts with full user rights, Microsoft warned.

Computers that connect to remote corporate networks via untrusted networks such as wi-fi hotspots are most at risk from JASBUG, Microsoft said. There are no mitigating factors or workarounds available for JASBUG.

All current versions of Windows desktop and Server operating systems are affected by JASBUG and will receive patches via Windows Update.

Administrators must also apply new AD Group Policy settings to protect against the vulnerability.

But no update is available for Windows Server 2003 - Microsoft said it would require significant re-architecting of the operating system, which is being made obsolete this year.

The open source SAMBA SMB/CIFS file server and Active Directory Domain Controller is unlikely to be vulnerable to JASBUG, project co-founder Jeremy Allison told iTnews.

"This is a client vulnerability when downloading files specified by Group Policy settings. As SAMBA clients don't download Group Policy settings, I don't believe we are affected," Allison said.

He said Microsoft notifies the project's security officers if they find vulnerabilities in the SAMBA code.

Further critical vulnerabilities plugged

The company also issued other updates today as part of its regular Patch Tuesday cycle.

Among these is a set of fixes for 41 vulnerabilities in Microsoft's Internet Explorer web browser. Microsoft rates the patch batch as critical in its MS15-009 security bulletin, since most of the vulnerabilities discovered can be exploited remotely for code execution.

Another flaw rated as critical affects the Windows kernel mode driver. Microsoft has patched six vulnerabilities in Windows that could permit remote code execution if a user opens a specially crafted document, or visits a website with embedded TrueType fonts.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
active directorygroup policyjasbugmicrosoftsecurityvulnerabilitywindowswindows server

Partner Content

Matt Tett to lead essential primer session on security by design
Partner Content Matt Tett to lead essential primer session on security by design
Security "mindset shift" needed to protect organisations
Promoted Content Security "mindset shift" needed to protect organisations
"We're seeing some good policy put in place, but that's the exception"
Partner Content "We're seeing some good policy put in place, but that's the exception"
Don't miss Australia’s premiere IoT Conference on 9th June
Promoted Content Don't miss Australia’s premiere IoT Conference on 9th June

Sponsored Whitepapers

Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership
Don’t pay the ransom: A three-step guide to ransomware protection
Don’t pay the ransom: A three-step guide to ransomware protection

Events

  • iTnews Benchmark Awards 2022 - Finalist Showcase
  • IoT Impact Conference
  • Cyber Security for Government Summit
By Juha Saarinen
Feb 11 2015
6:25AM
0 Comments

Related Articles

  • Researchers accidentally publish 'PrintNightmare' Stuxnet-style zero-day
  • Active Directory defaults lead to no-fix PrivEsc vulnerability
  • 'Single account' compromise led to Microsoft's Lapsus$ code leak
  • Exchange Server code execution vulnerability patched
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

NBN Co sizes up six-figure customer exodus a year to fixed wireless

NBN Co sizes up six-figure customer exodus a year to fixed wireless

NBN Co to cut 160 applications under $200m IT simplification

NBN Co to cut 160 applications under $200m IT simplification

NBN Co's 250Mbps and gigabit growth is finally clear

NBN Co's 250Mbps and gigabit growth is finally clear

What to expect from the incoming Labor government

What to expect from the incoming Labor government

Digital Nation

Lendlease launches its own metaverse in Milan
Lendlease launches its own metaverse in Milan
CTO Juergen Mueller offers a glimpse into SAP's metaverse play
CTO Juergen Mueller offers a glimpse into SAP's metaverse play
Why do DeFi and DAOs matter to business?
Why do DeFi and DAOs matter to business?
COVER STORY: Data and IoT set digital agriculture on a sustainable future
COVER STORY: Data and IoT set digital agriculture on a sustainable future
COVER STORY: A Year in the Metaverse
COVER STORY: A Year in the Metaverse
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.