Showing posts with label WSUS. Show all posts
Showing posts with label WSUS. Show all posts

Tuesday, 25 August 2015

Manual Windows Updaters Warned Patch


Microsoft has warned users and administrators to manually update computers for an important security update that was re-released and needs to be reinstalled. On August 11, Microsoft wrote poetry different vulnerabilities in Windows, .NET Framework, Office, Lync and Silverlight.

Through the vulnerabilities could take over a computer attacker completely if the user opens a specially crafted document or visit untrustworthy sites with embedded TrueType or OpenType fonts. As a solution has published Microsoft Security Bulletin  MS15-080. This update is on most Windows computers automatically installed via Windows Update. However, it is also possible to download the update from the Microsoft Download Center.

The update for Vista SP2, Windows Server 2008 (R2) SP2 and Windows 7 SP1 via the Download Center offered is updated on August 18th. Microsoft recommends that Windows users who update for August 18 have been downloaded from the Download Center to download it again and install so that they are fully protected against the vulnerabilities listed in the bulletin. This only applies to people who have downloaded the update from the Download Center. Users who update from Windows Update, Windows Update Catalog and WSUS are deployed need to take any action.

Saturday, 8 August 2015

WSUS Allows Attacker Distribute Infected Windows Updates



Companies and organizations that their Windows Server Update Services (WSUS) have not configured securely give attackers the ability to provide the entire corporate network from infected Windows updates.WSUS acts as a proxy for Windows Update. Companies can deploy effectively via WSUS Windows updates within their local network.

Instead of all company computers to connect to Microsoft servers to download updates, this is done once by WSUS. The WSUS server is installed in the corporate network and all connected business computers then will their Windows updates downloaded from the WSUS server. By default, WSUS, however not enabled to use HTTPS. An attacker who already has access to the corporate network can use to take then other company computers.

That researchers Paul Stone and Alex Chapman at the Black Hat conference demonstrated in Las Vegas ( pdf ). To prevent attacks via Windows Updates Windows only accepts updates that are signed by Microsoft. The researchers showed that an attacker Microsoft signed files can reuse to inject malicious updates, which are then to execute arbitrary commands on the attacked computers.

The attack, according to Stone and Chapman easy to avoid, namely setting up SSL. Most companies would also do this, so let them versus SC Magazine know. Companies, however, have not brought the risk that a system at one time the entire corporate network can compromise, the researchers said. In addition to enabling SSL by companies that use WSUS, Microsoft may also screwing security. The software giant would namely to use a separate certificate for the signings of Windows updates.