[ad_1]
On March 15, 2022, a authorities flash bulletin was printed describing how state-sponsored cyber actors have been ready to make use of the PrintNightmare vulnerability (CVE-2021-34527) along with bypassing Duo 2FA to compromise an unpatched Home windows machine and achieve administrative privileges.
This situation did not leverage or reveal a vulnerability in Duo software program or infrastructure, however made use of a mixture of configurations in each Duo and Home windows that may be mitigated in coverage. Duo recommends reviewing your configuration to ensure it meets your present enterprise and safety wants. Steering is supplied within the Suggestions and Greatest Practices part of this weblog.
In accordance with the FBI’s bulletin, cyber actors have been capable of receive entry to major credentials for customers with Duo accounts that didn’t have an enrolled multi-factor authentication (MFA) machine. This exercise was documented as early as Could, 2021. The actors have been then capable of enroll their very own MFA machine and as soon as enrolled, to make use of these accounts to compromise a Home windows system with Duo Authentication for Home windows Logon put in. As soon as logged into Home windows, menace actors exploited an unpatched PrintNightmare vulnerability (CVE-2021-34527) to achieve administrative privileges and redirect Duo two-factor authentication calls away from Duo’s cloud service, successfully bypassing 2FA with a purpose to achieve entry to the sufferer’s information.
The affect of the reported incident was the menace actor having access to the sufferer’s cloud storage and electronic mail surroundings.
On a broader stage, the affect of an incident like this one reminds us that sustaining a excessive safety posture is of utmost significance.
Permitting for self-enrollment for brand spanking new customers and returning customers is an business commonplace. We’ve examined and verified that main MFA/Entry suppliers typically by default permit enrollment of unenrolled customers with out another measures. The explanation for that is to make sure safety, but in addition to scale back friction for IT help and finish customers.
Suggestions and Greatest Practices
Common Greatest Practices:
- Require complicated or sturdy major consumer passwords
- Configure password lockout insurance policies to thwart brute-force password assaults
- Guarantee all of your methods have up-to-date safety patches
- Make the most of file integrity monitoring (set alerts on any modification of information on the Area Controller)
Duo Suggestions:
Observe: Snort signature IDs (SIDs) 57876 and 57877 have been launched to deal with the  PrintNightmare vulnerability.
Â
Share:
[ad_2]
