In a record-setting August release, Microsoft issued 14 security bulletins to address 34 vulnerabilities, 14 of them rated as critical. The flaws span Windows and Office, Internet Explorer, Silverlight and SQL.
Joshua Talbot, security intelligence manager for Symantec Security Response, is shining a light on the SMB pool overflow vulnerability. As he sees it, this should be a real concern for enterprises.
“Not only does it give an attacker system-level access to a compromised SMB server, but the vulnerability occurs before authentication is required from computers contacting the server,” Talbot said. “This means any system allowing remote access and not protected by a firewall is at risk.”
Beyond Best Practices
Although best practices dictate file- or print-sharing services, such as SMB servers, should not be open to the Internet, Talbot said such services are often unprotected from neighboring systems on local networks. That paves the way for cybercriminals to use a multi-staged attack.
“Such an attack would likely start by compromising an employee’s machine via a drive-by download or a socially engineered e-mail, and would end by using that compromised computer to attack neighboring machines on the same local network that has the SMB service running,” Talbot said.
This affects more than just file servers using the SMB service. Talbot said workstations that have enabled file and print sharing are also at risk. “Laptops with this configuration that connect to untrusted networks, such as public Wi-Fi, or that allow ad hoc connections could be attacked by neighboring computers,” he warned. “The user could then unwittingly carry their infected system back to the enterprise, opening the door to an organization’s entire network.”
Movies to Malware
SMB servers aside, August is another movies-to-malware month for Microsoft, according to Andrew Storms, director of security operations at nCircle. Four of the 14 bulletins this month fix bugs in media applications….