- These vulnerabilities affect: All current versions of Windows
- How an attacker exploits them: By tricking your users into running a .bat or .cmd file from a network location
- Impact: In the worst case, an attacker can gain complete control of your Windows computer
- What to do: Install the appropriate Microsoft patches as soon as possible, or let Windows Automatic Update do it for you
As part of Patch Day, Microsoft released a Windows security bulletin describing a code execution vulnerability involving the way it handles .bat and .cmd files, otherwise known as Windows batch files. Windows batch files allow you to write multiple, scripted commands which will run together (as a batch) when you run the file. Window’s suffers from a vulnerability in they way they process these files, which attackers could exploit to execute arbitrary code. If an attacker can trick one of your users into running a .bat or .cmd file from a network location, they could exploit this issue to execute any code with that user’s privileged. In most Windows environments, users have local administrator privileges, so this attack could give hackers full control of your machine.
That said, this flaw takes significant user interaction to succeed, and most savvy Windows users know batch files could be dangerous, and don’t run them randomly. Nonetheless, we recommend you patch Windows as soon as you can.
Also note, this will be the last security update for Windows XP. If you haven’t figured out your Windows XP migration path yet, you really should start thinking about it. That said, security companies like WatchGuard will continue to develop IPS and anti-malware signatures to detect and block threats against Windows XP systems. If you absolutely cannot upgrade XP, be sure to at least implement IPS, AV, and UTM systems to protect your vulnerable computers.
Microsoft has released updates that correct this vulnerability. You should download, test, and deploy the appropriate update throughout your network as soon as you can. If you choose, you can also let Windows Update automatically download and install them for you. As always, you should test your updates before deploying them. Especially, server related updates.
For All WatchGuard Users:
Though WatchGuard’s XTM appliances offer defenses that can mitigate some of the risk of this flaw (such as allowing you to block .bat and cmd files, or enabling GAV or IPS services to detect attacks and the malware they distribute), attackers can exploit it over the local network too. Since your gateway XTM appliance can’t protect you against local attacks, we recommend you install Microsoft’s updates to completely protect yourself from these flaws.
Microsoft has released patches correcting these issues.
- Microsoft Security Bulletin MS14-019
This alert was researched and written by Corey Nachreiner, CISSP (@SecAdept).
What did you think of this alert? Let us know at [email protected].
Leave a Reply