PSA: If you're still giving users admin rights, maybe try not doing that. Would've helped dampen 100+ Microsoft vulns last year – report
- Reference: 1615967112
- News link: https://www.theregister.co.uk/2021/03/17/microsoft_vulns_admin_rights/
- Source link:
Restricting privileges is infosec 101: as Microsoft [1]explains here , it limits the amount of damage or change an individual can do, which is especially thankful when their account is hijacked. However, there are businesses and groups out there that are, for instance, pressured internally into handing people admin rights to keep folks working with awkward software deployments.
[2]
BeyondTrust – which has a clear commercial interest here as it sells tools that manage privileged access – gives an example of an overworked IT support desk granting users long-term special rights to perform tasks to stop them filing new tickets each time they need to access something.
The stateside biz brings this up because it analyzed 1,268 CVE-listed bugs fixed in Microsoft products and services during 2020, and concluded, in a [3]report out this week, that the exploitation of more than half of the 196 critical-rated vulnerabilities – 109 to be exact – could have been mitigated by removing admin rights from users.
[4]
You're an admin! You're an admin! You're all admins, thanks to this Microsoft Exchange zero-day and exploit [5]FROM 2019
Interestingly enough, the biz observed that the number of patched privilege-escalation bugs in Microsoft's software increased year-on-year in 2020. That, we're told, highlights the valuable nature of admin-level access – that gaining remote code execution is not enough, privileged access is desirable, too – and therefore it adds more weight to reducing users' admin rights. If Microsoft is battling to keep privilege elevation down, why not follow suit and make life harder for miscreants by not handing out admin-level powers unnecessarily.
Don't forget, though, that according to Kenna Security's findings from February, [6]just 2.6 per cent of CVE-listed bugs discovered in 2019 were actively exploited in the wild. So even though removing admin rights from users may have limited the exploitation of X per cent of flaws, very few of them would have been exploited anyway in the real world.
Though, the earlier point stands: restricting admin-level control is a good thing. As BeyondTrust CTO Morey Haber put it to El Reg , "Why would anyone, or any organization, allow a user to browse the internet with administrative privileges?"
It literally just buys organisations time to patch and mitigates threats from opportunistic attacks
Haber did stress that removing people's admin rights is not a shortcut to proper security. "While removing administrative privileges mitigates the threats from a large variety of Microsoft vulnerabilities," he told us, "it is not a permanent solution. It literally just buys organisations time to patch and mitigates threats from opportunistic attacks. In the end, patching is the only permanent fix."
March has so far seen Microsoft and the entire infosec industry urging organizations to [7]patch exploitable security weaknesses in Exchange Server in the wake of the Hafnium crew targeting vulnerable deployments. This week brought warnings from Slovak infosec biz ESET that [8]six seemingly state-sponsored crews were using zero-day exploits against the software to compromise victims before patches were made available.
[9]
Microsoft has also released what it bills as a [10]"one click" mitigation tool aimed at orgs with on-prem Exchange deployments, saying: "This new tool is designed as an interim mitigation for customers who are unfamiliar with the patch/update process or who have not yet applied the on-premises Exchange security update." ®
Get our [11]Tech Resources
[1] https://docs.microsoft.com/en-us/services-hub/health/remediation-steps-ad/review-and-reduce-the-number-of-accounts-in-highly-privileged-administrative-groups
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YFHhS1O6VWBJRXGr4PxtdgAAAM4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.beyondtrust.com/blog/entry/microsoft-vulnerabilities-report
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YFHhS1O6VWBJRXGr4PxtdgAAAM4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2019/01/25/microsoft_exchange_domain_admin_eop/
[6] https://www.theregister.com/2021/02/18/cve_exploitation_2_6pc_kenna_security/
[7] https://www.theregister.com/2021/03/03/hafnium_exchange_server_attack/
[8] https://www.theregister.com/2021/03/15/in_brief_security/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YFHhS1O6VWBJRXGr4PxtdgAAAM4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://msrc-blog.microsoft.com/2021/03/15/one-click-microsoft-exchange-on-premises-mitigation-tool-march-2021/
[11] https://whitepapers.theregister.com/
Re: Surely there must be a better way to do this
There is. Your company just isn't ready to hear it ... and probably never will be. That's what happens when unqualified people make purchasing decisions.
Re: Surely there must be a better way to do this
I hope for your sake that what you actually mean is that you have *another* *login* with Admin rights, not that you *normally* have Admin rights. Admin rights are just that - for doing Admin, not for normal use.
Re: Surely there must be a better way to do this
There is. It's an IT dept that's in-house, not out-sourced, and properly managed so that staff realise that they're actually an integral part of the company and keeping the company secure and productive is essential to paying their wages.
Re: Surely there must be a better way to do this
I too wish for a better way. At my company we have started a new round of updating with new computers and I have been trying to deploy without the users having admin rights. Really quite troublesome, users can't install printers whose drivers are hosted on our own servers, and as noted previously can't even kill off wayward programs as they can't even bring up task manager. I do like that they can't install random software but ease of use is definitely not getting any high scores.
Better idea.
Get rid of Redmond products entirely.
Me DearOldMum, Wife and Great Aunt run a cut-down version of Slackware. None of them have ever used root, not even with su or sudo. Between the three of them, they needed precisely zero technical support in all of 2020. Right tool for the job and all that. (I handle their software updates and backups from my desk here in the office ... or rather a computer does it for me. A simple cron job or two and some scripting takes care of those details, with only very occasional input from me.)
My sister, on the other hand, who insists that if she doesn't run Windows the entire planet will implode, is constantly trying to get me to fix her computers ... Sorry, Sis, I don't do Windows.
Re: Better idea.
I'm missing the point you're trying to make here, provided there is one apart from your constant moans about Windows.
The article is saying that user accounts should not have admin rights. I think we agree on that. You apply that rule within your family. I do within mine, and I'm sure many El Reg readers do the same.
My pre-retirement second career was as a (mostly Windows, but some Mac and Linux) network manager. Of course the users did not get admin rights. The only real inconvenience to them was that they couldn't have Spotify. If they really did need something I'd set up the deployment and they'd get the thing they asked for pushed to their machine the next time they connected. Same with patches.
This is all common sense and standard practice in any sensible organisation. This article is not talking about sensible organisations.
What point does the Pavlovian anti-Windows comments serve? Especially as your last sentence suggests you're not exactly a Windows expert.
Re: Better idea.
When I first went contracting I bought a shiny new Mac, happy to be free of Redmond's heavy chains. Then I had to buy Office 2011 for the Mac cos all my clients used MS Office and the freeware incompatibilities were unprofessional at best and unmanageable at worst. Then I had to get an add-on for Mail cos Mac mail couldn't process calendar invites from some clients with Outlook. Then I transitioned all my mail, calendar and contacts to Outlook 2011 because one client couldn't receive my emails. Then I had to buy Parallels so I could buy Windows so I could buy MS Project cos that's what clients used and there was no Mac alternative (there is, but it took me years to find it). I've also got a 365 account because a client used Sharepoint.
Getting rid of MS products is easy if you haven't got any customers, suppliers or employees.
Re: Better idea.
Macs and mail! I occasionally receive emails which appear to be blank or allegedly include images which I can't see. Then I realise they're from Mac or iGadget users and have defaulted to sending HTML mail that's partly or entirely invisible to a mail client that's set up to be secure, i.e. expect plain text.
It's not just users but sloppy development, or lack of development resource by the vendor, means a lot of legacy applications demand excessive rights as well as out of date dependencies before they will work.
It's not as big a problem as it used to be but it's still there. Particularly bad with behemoth suppliers of near monopoly niche systems.
It used to be much worse, say, 10 years ago. Now it is mostly software installs, but that always comes with the baggage of 1) security = "Do we want that software on our machines?" and 2) licenses, "it might be free for personal use, but is it free for commercial use as well?" and "Whose cost centre is paying for it and do we have already unused licenses for that?"
I am actually happy that at work I can hand both issues over to people that are paid to do that and focus on my stuff. Yeah, it took me a few weeks to get everything in the beginning (mostly because of licensing question for software hitherto unused here), but I did have enough other things to work on. Plus there are (virtual) machines that are segregated from the normal networks where you can install things yourself, mostly for testing and evaluation purposes, and you can spin these VMs up with little effort (assuming you choose one of our standard OS). Installing software with a downloader-installer instead of a regular installer is a hassle though (I'm looking at you, Visual Studio).
At home I do have admin accounts on my machines, and have no problem doing regular patches, software updates, backups, ...
You're right about legacy apploications but things need to be seriously old to cause that sort of problem. The real problem I've encountered these days on Windows systems is apps that insist on installing to places they shouldn't such as Appdata. They do this in an attempt to get round access controls on Program Files. But any sensible shop not allow code to run from Appdata.
Yes, it can be fixed using, e.g., Applocker, but it's a pain in the arse.
It's not just users but sloppy development, or lack of development resource by the vendor, means a lot of legacy applications demand excessive rights as well as out of date dependencies before they will work.
In my reasonably extensive experiance (up to enterprise level) almost all legacy applications where people say "it needs admin permissions" usually actually just want write access to their installation folder, and occasionally to the folder where their dependancies from another company are stored. Digging under the surface you'll usually find that these programs started life prior to XP/NTFS when access permissions weren't a thing and were feature complete by around 2000 and haven't seen much development in the last 20 years beyond periodic reskins to make the GUI look less outdated and minor feature tweaks to deal with changes in the law.
This "problem" can be dealt with by right clicking on the installation folder and giving "users" write access to it. Giving somebody admin access to make these sort of programs work is like using a nuke to crack a nut.
Why do I need admin rights? Well, because of IT
The title says it all. I work in a company where admin rights were (recently-ish) withdrawn, but there's no software request or release process. So when I urgently needed a piece of software for a customer presentation, I wasted two days trying to work out how to get it installed on my workstation because - while every other process known to man was designed (badly) and published (better), the 'non-previously-approved software' process seems to not have been a prerequisite to withdrawing admin rights. And of course IT support is designed so that the poor sods on the helldesk are your only point of contact. Everyone with the ability to *do* something is heavily shielded from the coalface.
Re: Why do I need admin rights? Well, because of IT
I wouldn't say it is because of IT. Unless they are the poor sods who have to formulate the processes for your change requests. There should be a local change management for that. Yeah, this process management stuff is boring. Really boring. I'm glad I don't have to do it (much). Coming up with a good process flow is also hard! I know, I am involved in other (ITSM) processes. We did have to start close to zero as well. I'd rather focus more on programming and data science, but that's another two months away, I guess.
I am actually really happy that my company does have these processes in place - no, they are not perfect (far from it), and sometimes things get messed up, but in general the "standard" stuff (i.e. software that others have already requested) can be rolled out with relative ease. Assuming the licenses are there already...
So: yeah, it is a problem, I totally agree with you, but management should know about it and do something, maybe hire people to come up with a process, document it and test it. No, it is not as sexy as coming up with crypto-blockchain-empowered-whatever.
Re: Why do I need admin rights? Well, because of IT
It sounds as if your IT is either outsourced or lining itself up to be outsourced whether it intends that or not. In-house IT staff, and especially manglement, need to realise that it's what the rest of the company does that pays their wages and that it's in their own interests to make sure that they support that fully.
An IT department that's so disconnected that it might as well be in India is likely to find itself out on the street and replaced by one that is in India. Getting out of the the office/cubes and going to talk to some of the users is a Good Idea.
there really needs to be more options in corporate IT world to enable scientific computing staff to run different operating systems from the office droids. I've worked on locked-down Windows environments for years and frequently ended up using my own computer for work because the corporate sanctioned Windows box was useless. It's 2021 and IT is still a blocker more than an enabler.
A critical but overlooked matter
One of the most important areas where restricted rights is critical is in the web browser. The whole world (statistically speaking) allows anyone to run untrusted and essentially unverifiable scripts on your computer when you visit a web site. As JS is, and has been for ages, the primary vector for practically all client side compromises, this doesn't seem a very good idea. However it's increasingly being forced on everyone by web developers, even to the point where without scripting enabled web services simply don't function at all. So we're being forced to expose ourselves to compromise just in order to use the web, despite in many cases the function being offered being implementable safely and effectively without the use of scripting at all (e.g. loading images, displaying menus, submitting flat forms).
Surely there must be a better way to do this
Thank god I've got Admin rights on my machine! We've tried doing it without Admin rights but it just becomes a nightmare of perpetual waiting for responses from IT. e.g. Getting all your software installed on a new machine can take 2-3 weeks with 20 emails and 6 hours of calls if we rely on IT, instead of 1 hour if we just do it ourselves.
I do actually wish I didn't need Admin rights, but life would be so much harder without them. 24-48hr waits for a 2min change is not something I'd look forward to. And as for killing processes that have gone haywire/stuck I'd rather not my only option be to restart the machine.