It is now widely accepted that there will always be bugs and that vulnerabilities will always exist somewhere in IT systems. Calculated risks are still risks, but they feel somewhat under control. Yet sometimes a problem emerges that makes everyone think: so simple, so dangerous, with such far-reaching consequences? Surely that cannot be right?
Remote Desktop problem
Bluekeep (CVE-2019-0708) is one such example. A recently discovered bug in Microsoft's widely used RDP (Remote Desktop Protocol) turns out to leave the front door wide open, allowing unauthorised users to access the underlying systems and data. With all the major risks that entails: theft and misuse of personal or commercially sensitive data, interference with IT systems and business processes, malware infections and reputational damage.
Bluekeep is very dangerous. It gives cybercriminals access at the highest system security level within the terminal server, from which they can attack other servers and desktops in the business environment. They gain this access even without knowing the admin login details (…). Of course, gaining access to vulnerable RDP systems requires some action: the Bluekeep bug must be exploited and vulnerable servers found. For those in the know (cybercriminals), however, this turns out not to be very difficult. With a little experience, you can develop your own Bluekeep exploit in a few hours, and an internet scanner or bot makes it easy to find potentially vulnerable servers. It will surely not be long before these tools are available ready-made on a dark web marketplace.
Can nothing be done? Microsoft states that the RDP protocol itself is not vulnerable; the bug is in the Remote Desktop Services process included as standard in every version of Windows. It only affects older desktop and server editions, such as Windows 7 and XP and Server 2008 and 2003. These systems have long been superseded by newer, more secure editions, but remain widely used in practice. There are easy and less easy remedies: disabling RDP, blocking public RDP access at the firewall (we have advised this for more than 10 years, and no, not even 'on a different port'), or, logically, updating the vulnerable software.
Pulse Secure and Fortinet SSL VPN
Alongside Bluekeep, it also emerged that several SSL VPN services have critical vulnerabilities that sometimes make access to data and systems child's play. Yet the very reason for choosing Virtual Private Networking over properly encrypted data connections is to keep communications secure and well protected. (CVE-2019-11510 and CVE-2019-11539)
Pulse Secure SSL VPN connections are widely used in large-scale environments within government bodies and major companies. The vulnerability is so simple that the risks and resulting damage can be enormous. A simple HTTPS attack can readily provide access to VPN systems, both servers and clients, exposing the underlying systems and data to intruders. At a recent Black Hat event, the Pulse Secure security flaw was even given the highest possible risk rating. Many systems are now demonstrably being attacked through exploits that use these vulnerabilities.
With the SSL VPN solutions from Fortinet, a firewall supplier widely used in medium-sized and large corporate networks, it turns out to be possible to retrieve system login credentials and use them to gain access. (CVE-2018-13379 and CVE-2018-13383 and more information) These firewalls are mainly used to connect corporate networks to the internet, leaving the companies and their valuable data highly vulnerable to abuse.
The problems affecting both Pulse Secure and Fortinet have been known for some time and resolved through software changes. In practice, however, many systems have not been updated, leaving the vulnerabilities unresolved.
The solution: Continuous Scan & Response
Both Bluekeep and the SSL VPN issues affecting Pulse Secure and Fortinet stem from the same problem: systems have not been updated with the correct patches and latest software releases, leaving them behind the changes and recommendations from the relevant manufacturers. But vulnerabilities sometimes lie elsewhere too: incorrect or incomplete implementation, conflicts between different products, permissions structures or authentication applications, and even manual changes to processes (see DigiNotar).
Continuous Scan & Response investigates these different types of vulnerabilities and presents them clearly, so that appropriate action can be taken in time. Would you like to know how SECWATCH can help your business keep the back doors shut without leaving the front door wide open? Contact us for a no-obligation discussion about our Vulnerability Management solutions and prevent problems.
