Electoral Commission had internet-facing server with unpatched vuln
- Reference: 1691754469
- News link: https://www.theregister.co.uk/2023/08/11/electoral_commission_vulnerability/
- Source link:
Earlier this week, the election oversight body [1]disclosed that its systems had been broken into, and the attackers had access to the servers that host the organization's email, as well as copies of the electoral registers for the entire UK.
It appears the Electoral Commission was running Microsoft Exchange Server with Outlook Web App (OWA) facing the internet, and was vulnerable to an exploit known as ProxyNotShell at the time that suspicious activity was first detected on the Commission’s systems in [2]October 2022 .
[3]
The ProxyNotShell vulnerability is a weakness in how Microsoft handles authentication requests. It includes two security bugs, tracked as [4]CVE-2022-41082 and CVE-2022-41040 , that can be exploited together to run PowerShell commands on a vulnerable system and take control of it.
[5]
[6]
According to security researcher Kevin Beaumont, the Electoral Commission’s Microsoft Exchange Server was visible online until at least late September 2022, after which it dropped offline. This corresponds with the discovery of ProxyNotShell, which was already being exploited, and for which no security patch was available for some time.
The version of Microsoft Exchange Server that was running at the time was 15.1.2507.12, which corresponds to Exchange Server 2016, last security updated in August 2022. This means the Electoral Commission (or their IT supplier) was at least applying security patches quickly during this time, Beaumont noted in a [7]posting on Medium.
Chief of NI police issues update as dissident Irish republican claim they have cop data text
The other security incident this week was the [8]erroneous disclosure of details regarding all serving officers in the Police Service of Northern Ireland (PSNI), which may have placed some officers at risk.
In an update yesterday, Chief Constable Simon Byrne met members of the PSNI Executive Team to discuss the issue and any steps necessary to ensure such an incident does not happen again.
It was reported that dissident Irish republicans claim to be in possession of the data, which lists the names, rank and location and department in which officers work. It was already feared the data might be used to intimidate, corrupt or harm officers or staff.
The problem, however, was it took Redmond until early November 2022 to deliver a security update that finally fixed the bugs and resolved the vulnerability issue. In the intervening time, the software giant had issued [9]several mitigations , but all of these temporary fixes were quickly bypassed.
This doesn’t necessarily prove that ProxyNotShell is the way that the attackers were able to gain access to the Electoral Commission systems. For one thing, the organization reported that its systems had first been accessed more than a year earlier, in August 2021.
[10]
However, ProxyNotShell would have made it much easier for the attackers to do pretty much anything they wanted, once the vulnerability was known about. As Beaumont states: “ProxyNotShell allows remote code execution on the Exchange email server, or in other words complete compromise of the network (Exchange Server runs with highly privileged Active Directory accounts by default).”
[11]Microsoft, Intel lead this month's security fix emissions
[12]Microsoft to enterprises: Patch your Exchange servers
[13]Five Eyes nations detail dirty dozen most exploited vulnerabilities
[14]Sneaky Python package security fixes help no one – except miscreants
ProxyNotShell was the enabler in several other security breaches, most notably one that [15]hit Rackspace in December last year and was so disastrous that it led to the company completely discontinuing its hosted Microsoft Exchange email service.
Beaumont said that Microsoft needs to ship security patches for Microsoft Exchange Server faster, and organizations which expose Exchange Server to the internet need to be aware that it will get targeted, and implement enhanced security monitoring and containment. ®
Get our [16]Tech Resources
[1] https://www.theregister.com/2023/08/08/uk_electoral_commission_hacked_voter/
[2] https://www.theregister.com/2022/10/11/october_patch_tuesday/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZNZbJq6409qwZ1iR@LWZyQAAAY4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.theregister.com/2022/11/09/microsoft_november_2022_patch_tuesday/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNZbJq6409qwZ1iR@LWZyQAAAY4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZNZbJq6409qwZ1iR@LWZyQAAAY4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://doublepulsar.com/uk-electoral-commission-had-an-unpatched-microsoft-exchange-server-vulnerability-5436f3f5ec2c
[8] https://www.theregister.com/2023/08/09/psni_data_breach/
[9] https://www.theregister.com/2022/10/11/october_patch_tuesday/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNZbJq6409qwZ1iR@LWZyQAAAY4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://www.theregister.com/2023/08/08/microsoft_intel_august_patch_tuesday/
[12] https://www.theregister.com/2023/01/28/microsoft_patch_exchange_servers/
[13] https://www.theregister.com/2023/08/07/in_brief_security/
[14] https://www.theregister.com/2023/07/26/python_silent_security_fixes/
[15] https://www.theregister.com/2023/01/05/rackspace_ransomware_gang/
[16] https://whitepapers.theregister.com/
Not only the first comment, probably the best comment. You win the internet for today.
Sigh
When will they learn?
Re: Sigh
Never.
"highly privileged Active Directory accounts by default"
For am email server. How typical of Borkzilla.
We don't know how to do security efficiently, so let's just give email all the privileges and it will work. What's the worst that could happen ?
Hey Nadella, here's a challenge : get Exchange working on Linux.
That'll teach you a thing or two about actual security.
Re: "highly privileged Active Directory accounts by default"
MS employees downvoting you I see!
Exchange and AD on Linux are the two major remaining blockers to Linux Office desktop. And as everything office enterprise is subscription based licenses anyway....
Re: "highly privileged Active Directory accounts by default"
"That'll teach you a thing or two about actual security."
I'm not sure it would and I don't like to contemplate the consequences.
"Exchange Server runs with highly privileged Active Directory accounts by default..."
What a great idea.
But when every day I see the amateurish borkage that Microsoft continually perpetrates in the name of email, I suppose I shouldn't be surprised.
Yesterday they told me that an email that I didn't send had failed SPF verification.
Jerks.
"the attackers had access to the servers that host ... copies of the electoral registers for the entire UK"
So have the electoral registers been trawled? If that is, or suspected to be the case, why have impacted persons (ie the whole of Britain) not been notified that their personal information has been compromised?
Think we need to watch the ICO starting procedures to sue the company - that would be the Government - for whatever percentage of annual turnover is allowed under the current GDPR-ish regulations ...
Compare this with flying
If aircraft would be serviced, repaired and flown like servers are secured and maintained we would have the landscape full with crashed airplanes.
IT security is doable (OK, harder for zero days but even there a well-run outfit could think about possible mitigations before the fact). But as people usually don't die because of these idiots (alas, the PSNI leak may prove this to be wrong) we're fucked.
Re: Compare this with flying
Ultimately, it needs to be less accessible to everyone, with several people who know what they are doing checking what each other is doing.
Bu that costs money, is inconvenient, and would just be loudly complained about in the modern world of everything being instant.
Re: Compare this with flying
... don't die *directly*.
Simple question
Are you siting on data which you would absolutely have to get back if it was leaked?
Well, you can't get it back so the only option is to absolutely not let it leak.
Does this mean you can get a ProxyNotShell vote?