Overview
Microsoft Windows domain-configured client Group Policy fails to authenticate servers over Universal Naming Convention (UNC) paths.
Description
Microsoft has released MS15-011, detailing a critical flaw in which Windows domain-configured client Group Policy fails to authenticate servers over Universal Naming Convention (UNC) paths. Upon connecting to a network, Group Policy runs logon scripts to receive and apply policy data from a domain controller. By joining an attacker-controlled network, the vulnerable system will execute attacker-provided scripts since the server is not required to authenticate itself. Because of the way that the Multiple UNC Provider (MUP) iterates through UNC providers to establish a connection to the domain controller, the vulnerability may be remotely exploitable when a UNC path is resolved over the Internet. For more detailed information, visit Microsoft's blog about hardening Group Policy and JAS's JASBUG Fact Sheet. |
Impact
A remote, unauthenticated attacker may execute arbitrary code and completely compromise vulnerable systems. |
Solution
Apply an update and configure Group Policy settings |
Vendor Information
Many versions of Microsoft Windows operating systems are confirmed vulnerable, including:
Unsupported operating systems such as Microsoft Windows XP and 2000 may also be affected. |
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 10 | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Temporal | 7.8 | E:POC/RL:OF/RC:C |
Environmental | 8.5 | CDP:LM/TD:H/CR:ND/IR:ND/AR:ND |
References
- https://msdn.microsoft.com/en-us/library/gg465305.aspx
- https://technet.microsoft.com/en-us/library/security/ms15-011
- https://support.microsoft.com/kb/3000483
- http://blogs.technet.com/b/srd/archive/2015/02/10/ms15-011-amp-ms15-014-hardening-group-policy.aspx
- https://www.jasadvisors.com/about-jas/jasbug-security-vulnerability-fact-sheet/
Acknowledgements
Microsoft credits Jeff Schmidt of JAS Global Advisors, Dr. Arnoldo Muller-Molina of simMachines, and the Internet Corporation for Assigned Names and Numbers (ICANN) with discovering this issue.
This document was written by Joel Land.
Other Information
CVE IDs: | CVE-2015-0008 |
Date Public: | 2015-02-13 |
Date First Published: | 2015-02-13 |
Date Last Updated: | 2015-02-13 15:13 UTC |
Document Revision: | 21 |