News: 1691754469

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Electoral Commission had internet-facing server with unpatched vuln

(2023/08/11)


The hacking of the UK’s Electoral Commission was potentially facilitated by the exploitation of a vulnerability in Microsoft Exchange, according to a security expert.

Earlier this week, the election oversight body [1]disclosed that its systems had been broken into, and the attackers had access to the servers that host the organization's email, as well as copies of the electoral registers for the entire UK.

It appears the Electoral Commission was running Microsoft Exchange Server with Outlook Web App (OWA) facing the internet, and was vulnerable to an exploit known as ProxyNotShell at the time that suspicious activity was first detected on the Commission’s systems in [2]October 2022 .

[3]

The ProxyNotShell vulnerability is a weakness in how Microsoft handles authentication requests. It includes two security bugs, tracked as [4]CVE-2022-41082 and CVE-2022-41040 , that can be exploited together to run PowerShell commands on a vulnerable system and take control of it.

[5]

[6]

According to security researcher Kevin Beaumont, the Electoral Commission’s Microsoft Exchange Server was visible online until at least late September 2022, after which it dropped offline. This corresponds with the discovery of ProxyNotShell, which was already being exploited, and for which no security patch was available for some time.

The version of Microsoft Exchange Server that was running at the time was 15.1.2507.12, which corresponds to Exchange Server 2016, last security updated in August 2022. This means the Electoral Commission (or their IT supplier) was at least applying security patches quickly during this time, Beaumont noted in a [7]posting on Medium.

Chief of NI police issues update as dissident Irish republican claim they have cop data text

The other security incident this week was the [8]erroneous disclosure of details regarding all serving officers in the Police Service of Northern Ireland (PSNI), which may have placed some officers at risk.

In an update yesterday, Chief Constable Simon Byrne met members of the PSNI Executive Team to discuss the issue and any steps necessary to ensure such an incident does not happen again.

It was reported that dissident Irish republicans claim to be in possession of the data, which lists the names, rank and location and department in which officers work. It was already feared the data might be used to intimidate, corrupt or harm officers or staff.

The problem, however, was it took Redmond until early November 2022 to deliver a security update that finally fixed the bugs and resolved the vulnerability issue. In the intervening time, the software giant had issued [9]several mitigations , but all of these temporary fixes were quickly bypassed.

This doesn’t necessarily prove that ProxyNotShell is the way that the attackers were able to gain access to the Electoral Commission systems. For one thing, the organization reported that its systems had first been accessed more than a year earlier, in August 2021.

[10]

However, ProxyNotShell would have made it much easier for the attackers to do pretty much anything they wanted, once the vulnerability was known about. As Beaumont states: “ProxyNotShell allows remote code execution on the Exchange email server, or in other words complete compromise of the network (Exchange Server runs with highly privileged Active Directory accounts by default).”

[11]Microsoft, Intel lead this month's security fix emissions

[12]Microsoft to enterprises: Patch your Exchange servers

[13]Five Eyes nations detail dirty dozen most exploited vulnerabilities

[14]Sneaky Python package security fixes help no one – except miscreants

ProxyNotShell was the enabler in several other security breaches, most notably one that [15]hit Rackspace in December last year and was so disastrous that it led to the company completely discontinuing its hosted Microsoft Exchange email service.

Beaumont said that Microsoft needs to ship security patches for Microsoft Exchange Server faster, and organizations which expose Exchange Server to the internet need to be aware that it will get targeted, and implement enhanced security monitoring and containment. ®

Get our [16]Tech Resources



[1] https://www.theregister.com/2023/08/08/uk_electoral_commission_hacked_voter/

[2] https://www.theregister.com/2022/10/11/october_patch_tuesday/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZNZbJq6409qwZ1iR@LWZyQAAAY4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://www.theregister.com/2022/11/09/microsoft_november_2022_patch_tuesday/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNZbJq6409qwZ1iR@LWZyQAAAY4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZNZbJq6409qwZ1iR@LWZyQAAAY4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://doublepulsar.com/uk-electoral-commission-had-an-unpatched-microsoft-exchange-server-vulnerability-5436f3f5ec2c

[8] https://www.theregister.com/2023/08/09/psni_data_breach/

[9] https://www.theregister.com/2022/10/11/october_patch_tuesday/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNZbJq6409qwZ1iR@LWZyQAAAY4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://www.theregister.com/2023/08/08/microsoft_intel_august_patch_tuesday/

[12] https://www.theregister.com/2023/01/28/microsoft_patch_exchange_servers/

[13] https://www.theregister.com/2023/08/07/in_brief_security/

[14] https://www.theregister.com/2023/07/26/python_silent_security_fixes/

[15] https://www.theregister.com/2023/01/05/rackspace_ransomware_gang/

[16] https://whitepapers.theregister.com/



Korev

Does this mean you can get a ProxyNotShell vote?

Androgynous Cupboard

Not only the first comment, probably the best comment. You win the internet for today.

Sigh

Mr Dogshit

When will they learn?

Re: Sigh

Tams

Never.

"highly privileged Active Directory accounts by default"

Pascal Monett

For am email server. How typical of Borkzilla.

We don't know how to do security efficiently, so let's just give email all the privileges and it will work. What's the worst that could happen ?

Hey Nadella, here's a challenge : get Exchange working on Linux.

That'll teach you a thing or two about actual security.

Re: "highly privileged Active Directory accounts by default"

Binraider

MS employees downvoting you I see!

Exchange and AD on Linux are the two major remaining blockers to Linux Office desktop. And as everything office enterprise is subscription based licenses anyway....

Re: "highly privileged Active Directory accounts by default"

Doctor Syntax

"That'll teach you a thing or two about actual security."

I'm not sure it would and I don't like to contemplate the consequences.

sitta_europea

"Exchange Server runs with highly privileged Active Directory accounts by default..."

What a great idea.

But when every day I see the amateurish borkage that Microsoft continually perpetrates in the name of email, I suppose I shouldn't be surprised.

Yesterday they told me that an email that I didn't send had failed SPF verification.

Jerks.

Andy The Hat

"the attackers had access to the servers that host ... copies of the electoral registers for the entire UK"

So have the electoral registers been trawled? If that is, or suspected to be the case, why have impacted persons (ie the whole of Britain) not been notified that their personal information has been compromised?

Think we need to watch the ICO starting procedures to sue the company - that would be the Government - for whatever percentage of annual turnover is allowed under the current GDPR-ish regulations ...

Compare this with flying

jonha

If aircraft would be serviced, repaired and flown like servers are secured and maintained we would have the landscape full with crashed airplanes.

IT security is doable (OK, harder for zero days but even there a well-run outfit could think about possible mitigations before the fact). But as people usually don't die because of these idiots (alas, the PSNI leak may prove this to be wrong) we're fucked.

Re: Compare this with flying

Tams

Ultimately, it needs to be less accessible to everyone, with several people who know what they are doing checking what each other is doing.

Bu that costs money, is inconvenient, and would just be loudly complained about in the modern world of everything being instant.

Re: Compare this with flying

ChoHag

... don't die *directly*.

Simple question

Doctor Syntax

Are you siting on data which you would absolutely have to get back if it was leaked?

Well, you can't get it back so the only option is to absolutely not let it leak.

Here is the fact of the week, maybe even the fact of the month.
According to probably reliable sources, the Coca-Cola people are experiencing
severe marketing anxiety in China.
The words "Coca-Cola" translate into Chinese as either (depending
on the inflection) "wax-fattened mare" or "bite the wax tadpole".
Bite the wax tadpole.
There is a sort of rough justice, is there not?
The trouble with this fact, as lovely as it is, is that it's hard
to get a whole column out of it. I'd like to teach the world to bite a wax
tadpole. Coke -- it's the real wax-fattened mare. Not bad, but broad
satiric vistas do not open up.
-- John Carrol, The San Francisco Chronicle