New Windows flaw could allow a WannaCry like attack if not patched

Discussion in 'malware problems & news' started by itman, Aug 14, 2017.

  1. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    https://www.scmagazine.com/new-wind...ry-like-attack-if-not-patched/article/681698/
     
  2. NormanF

    NormanF Registered Member

    Joined:
    Feb 20, 2009
    Posts:
    2,882
    Not a problem for home users. Malware authors go where the money is - corporate networks.
     
  3. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
    So if you have search service disabled, you should be fine?
     
  4. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,508
    Exactly. That said, time to check up on things at work for me. Also, thanks for the heads up @itman
     
  5. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
  6. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
  7. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Appears the primary issue would be on an unpatched Enterprise based server or endpoint. Also appears the vulnerability is related to the service only. Believe its primary purpose is to facilitate indexing which some already have turned off. Ref.: https://msdn.microsoft.com/en-us/library/windows/desktop/aa965362(v=vs.85).aspx
     
  8. kram7750

    kram7750 Guest

    Well, disabling the search service would definitely decrease the chances of the vulnerability becoming exploited, however a malware sample could easily start the service manually via the service manager.

    Removing the Search would mitigate it for a manual fix (unless malware dropped it back onto the system and then used it), but for a practical mitigation it would require Microsoft to patch the vulnerability (and if it wasn't already patched, a security product could temporarily prevent unknown running processes from communicating with the Search service so the exploit cannot be deployed).

    But, messing with removing Windows components like the Search is not really practical and can cause potential problems. :)
     
    Last edited by a moderator: Aug 15, 2017
  9. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Also time to review basic SMB security:

    1. Using an IDS, access to admin shares should be blocked/restricted.
    2. Using a firewall, ports used by SMB, i.e. 137-138, and 445, should be restricted to local network access only.
     
  10. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Patching Against the Next WannaCry Vulnerability (CVE-2017-8620)
    http://www.securityweek.com/patching-against-next-wannacry-vulnerability-cve-2017-8620
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.