All articles

Why old vulnerabilities can suddenly become a serious threat to your network and systems years later

Many security vulnerabilities are more than five years old, some even more than ten (!) years old.

And the way many businesses now handle these “mature” threats makes them easy prey for hackers. In this article, we show you how that happened and what you can do about it.

Briefly

And we really mean very briefly: ten-year-old vulnerabilities can hit your organisation hard today. That is because many businesses do not apply updates.

You could stop reading now and march angrily into your IT department, but read on first. It will make that conversation with your tech experts much easier. 🙂

Because this is how it happens

EternalBlue (MS17-010), a vulnerability from 2017, is one example. During penetration tests, our testers still regularly encounter computers vulnerable to it. By placing a backdoor, this vulnerability allows an unauthorised user to gain access to a Windows computer. This happens without employee involvement and immediately grants the highest possible privileges. We call this a backdoor attack. A single vulnerable computer can therefore be enough to take over an entire network.

Dirty COW, which has existed since 2006 but was only discovered and exploited in 2016, is also a dangerous bug that allows systems to be taken over with root user access, the highest administrative account. This vulnerability threatens all Linux-based systems, including Android, and exists at kernel level.

Patches to protect against these vulnerabilities have been available to organisations for years. But because many organisations do not apply the updates, they remain vulnerable to cyber threats such as theft of sensitive business information or the installation of ransomware.

So why are updates not applied?

In short: focus and time! We see that organisations do not recognise the role of updates in cybercrime and that IT departments are given too little time to apply them. Organisations see ransomware as the main threat to their cybersecurity. But that is the “endgame” of cybercriminals deploying ransomware. As a result, IT departments receive insufficient time and capacity to apply updates.

To install ransomware, cybercriminals first need access to the network, for example through a phishing email. They then use vulnerabilities in the network that arose much earlier, such as EternalBlue and Dirty COW. And if the updates have not been applied…

Those cybercriminals may not be the only threat to your organisation. Hacking groups backed by foreign states often use the same vulnerabilities because they provide easy access to networks. For organisations in certain industries or supply chains, protection against them is therefore a must.

Without that protection, your security policy can become like mopping the floor with the tap running. You are simply not sufficiently protected. You lack control. While you may well be monitoring somewhere in your organisation, cybercriminals can stroll straight to your pot of gold. This is why we always make applying updates an absolute top priority.

See also our article how to protect your organisation against cyber threats when all hell breaks loose in the world: 12 steps.

How can I improve my security?

Fortunately, there are always sensible steps to take. Start with these five:

  1. Updating
    Check which software and systems are out of date and make sure you update all of them immediately. In many cases, that will be a substantial task; we understand that. But it immediately increases cyber resilience and reduces the attack surface.
  2. Insight
    Ensure complete visibility. Examine your technical setup. Check which systems, connection points and technical components are business-critical for your organisation. Create an overview of all software in use and the components used. Map patch status and the current state of vulnerabilities. Then assess the consequences of updating; if there are none, schedule and apply the updates. If there are consequences, such as software no longer working after a server update, consider whether mitigating measures can be taken. For security and risk management, the general advice is to focus on vulnerabilities with known exploits that are or could be actively exploited. Make this an ongoing process. Stay alert.
  3. Threat intelligence
    Map exactly which threats your organisation must protect against and whether any risks can or must be accepted. Start by asking yourself: which supply chain does your business operate in? Who is targeting us? Which attack techniques do they use? What are your dependencies on suppliers, and how secure are they? What do customers and other stakeholders expect of you?
  4. Urgency
    Create urgency in your policy: make updates an absolute priority, step 1 for a reason 😉. But also check whether your IT department or external IT provider has enough time and authority for this and whether sufficient knowledge is available in-house. If not, find a specialist who can establish this with you.
  5. Testing
    Test your current risk picture by commissioning a penetration test. After completing the steps above, it is worth approaching an independent party to map your risks. Hint: you are reading an article by one as we speak 😉. A good cybersecurity specialist looks at your business through a cybercriminal's eyes.

Need help from a real hacker?

We enjoy nothing more than thinking critically with you and sharing our view of your current situation. No more headaches over costly cyber threats? That can be arranged!

Schedule a free clarity call.


Back to all articles