{"id":47423,"date":"2022-08-10T07:45:00","date_gmt":"2022-08-10T07:45:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/47423"},"modified":"2022-08-10T07:45:00","modified_gmt":"2022-08-10T07:45:00","slug":"microsoft-fixes-two-year-old-msdt-vulnerability-in-august-update","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=47423","title":{"rendered":"Microsoft fixes two-year-old MSDT vulnerability in August update"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/08\/microsoft-fixes-two-year-old-msdt-vulnerability-in-august-update.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Two-and-a-half years after a security researcher <a href=\"https:\/\/irsl.medium.com\/the-trouble-with-microsofts-troubleshooters-6e32fc80b8bd\">publicly disclosed the existence<\/a>&nbsp;of a remote code execution (RCE) zero-day vulnerability in the Microsoft Windows Support Diagnostic Tool (MSDT), dubbed DogWalk, Microsoft has finally issued a fix for the problem after a new variant emerged, having previously not done so on the basis that it did not meet the right criteria.<\/p>\n<p>Tracked as <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-34713\">CVE-2022-34713<\/a>, successful exploitation requires the victim to be convinced to open a specially crafted file, which can be delivered either via email or an attacker-controlled or compromised website. As such, it is rated merely important as opposed to critical.<\/p>\n<p>This is the second major MSDT vulnerability to have been fixed by Microsoft in the past few months, following the disclosure of <a href=\"https:\/\/www.computerweekly.com\/news\/252520855\/Researchers-discover-zero-day-Microsoft-vulnerability-in-Office\">the dangerous Follina zero-day<\/a> at the end of May, which was <a href=\"https:\/\/www.techtarget.com\/searchwindowsserver\/news\/252521541\/Microsoft-fixes-Follina-zero-day-for-June-Patch-Tuesday\">patched in June<\/a>.<\/p>\n<p>\u201cWith reports that CVE-2022-34713 has been exploited in the wild, it would appear that attackers are looking to take advantage of flaws within MSDT as these types of flaws are extremely valuable to launch <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/definition\/spear-phishing\">spear phishing<\/a> attacks,\u201d said <a href=\"https:\/\/www.tenable.com\/\">Tenable<\/a> senior staff research engineer Satnam Narang.<\/p>\n<p>\u201cA variety of threat actors leverage spear phishing, from advanced persistent threat (APT) groups to ransomware affiliates,\u201d he said. \u201cFor attackers, bugs that can be executed via malicious documents remain a valuable tool, so flaws like Follina and CVE-2022-34713 will continue to be used for months. Therefore, it is vital that organisations apply the available patches as soon as possible.\u201d<\/p>\n<p>Qualys director of vulnerability and threat research Bharat Jogi added: \u201cThe&nbsp;DogWalk&nbsp;zero-day vulnerability is not new to the industry. It was initially reported back in 2019, but not deemed a vulnerability as it was&nbsp;believed to require significant user interaction to exploit, and there were various other mitigations in place.<\/p>\n<p>\u201cHowever, as we see today\u2019s bad actors growing more sophisticated and creative in their exploits,&nbsp;a recent zero-day&nbsp;that&nbsp;leveraged&nbsp;the&nbsp;ms:msdt&nbsp;protocol URI scheme (Follina) forced MSFT to reconsider&nbsp;DogWalk&nbsp;as a vulnerability,\u201d he said. \u201cFollina&nbsp;has been recently used by threat actors \u2013 for example, Chinese APT TA413 \u2013 in phishing campaigns that have&nbsp;targeted&nbsp;local US and&nbsp;European&nbsp;government personnel, as well as a major&nbsp;<a href=\"https:\/\/urldefense.proofpoint.com\/v2\/url?u=https-3A__decoded.avast.io_threatintel_outbreak-2Dof-2Dfollina-2Din-2Daustralia_&amp;d=DwMF-g&amp;c=tEbGsWWjqkBSpaWdXc_mdMSanI1bDu-FKXiKGCfVmPM&amp;r=OtdtH4YHQibTAzHjZLHmgv1-ClJ6pexybHUB-dtxpJ4&amp;m=_OIqaSZm-HLuBfrTUXeS8MzU4mFj82lUK_7zg1vkHGAgiaauIOouUu18XLPm-XR9&amp;s=4U8Zv7H9vpDdBW_X_LqxVM1Q5f91931ro3Ylw6vsDMM&amp;e=\">Australian telecommunications provider<\/a>.&nbsp;Successful exploitation of this vulnerability allows an attacker to deploy malware and gain foothold on a system.\u201d<\/p>\n<p>The August update fixes a larger-than-average total of 121 vulnerabilities, 17 of them classed as critical \u2013 likely in part due to disclosures and proof-of-concept exploits to be shown off at <a href=\"https:\/\/www.blackhat.com\/us-22\/\">Black Hat USA<\/a> and the upcoming <a href=\"https:\/\/defcon.org\/\">DEF CON<\/a> hacker event.<\/p>\n<p>Of the critical vulnerabilities, two of the most severe appear to be <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-30133\">CVE-2022-30133<\/a> and <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-35744\">CVE-2022-35744<\/a>, both of which are RCE vulnerabilities affecting Windows Point-to-Point Protocol, and both of which carry CVSS scores of 9.8, although neither has been made public or exploited. A full breakdown of this month\u2019s critical vulnerabilities is available from the <a href=\"https:\/\/www.zerodayinitiative.com\/blog\/2022\/8\/9\/the-august-2022-security-update-review\">Zero Day Initiative<\/a>.<\/p>\n<p>Also particularly noteworthy is a publicly disclosed but not-yet-exploited information disclosure vulnerability affecting Exchange Server, tracked as <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-30134\">CVE-2022-30134<\/a>. Greg Wiseman, lead product manager at <a href=\"https:\/\/www.rapid7.com\/\">Rapid7<\/a>, explained its significance:<\/p>\n<p>\u201cIn this case, simply patching is not sufficient to protect against attackers being able to read targeted email messages,\u201d he said. \u201cAdministrators should enable <a href=\"https:\/\/microsoft.github.io\/CSS-Exchange\/Security\/Extended-Protection\/\">Extended Protection<\/a> in order to fully remediate this vulnerability, as well as <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2022-21980\">the<\/a> <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2022-24516\">five<\/a> <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2022-24516\">other<\/a> <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2022-24477\">vulnerabilities<\/a> <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2022-34692\">affecting<\/a> Exchange this month. Details about how to accomplish this are available via the <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/exchange-team-blog\/released-august-2022-exchange-server-security-updates\/ba-p\/3593862\">Exchange Blog<\/a>.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Two-and-a-half years after a security researcher publicly disclosed the existence&nbsp;of a remote code execution (RCE) zero-day vulnerability in the Microsoft Windows Support Diagnostic Tool (MSDT), dubbed DogWalk, Microsoft has finally issued a fix for the problem after a new variant emerged, having previously not done so on the basis that it did not meet the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":47424,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-47423","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/47423","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=47423"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/47423\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/47424"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=47423"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=47423"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=47423"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}