Windows DCOM Server Authentication: Checking the Impact on Your Network
Recently, specifically at the end of last year, Microsoft improved authentication for its DCOM server. These measures were taken as part of a comprehensive response to a vulnerability discovered by a team of ethical hackers.
We will talk about these hackers, their code and rules in the next publications - follow ourblog.
In the meantime, let's test and check your network, as the developers are still testing the changes and have not yet made them permanent.
Follow us onFacebook,Telegram,Twitter or Instagramto be in trend!
The security update doesn't provide enough details about the underlying hardware, but it does provide enough information about how this change will impact the network environment of users and administrators.
These are updates and fixes for bugs that could allow DCOM (Component Object Model) server security to be bypassed.
So what exactly has been corrected? Only a bulletin from the Land of the Rising Sun sheds light on these nuances and offers clues. Below are the conclusions and useful information from the document.
Patch
The vulnerability was exploited in the following way: A DCOM client was prompted to connect to a pre-created server. To do this, a phishing message was sent in the form of an email or other communication channel. Logging in meant that the system had been taken over not by the original user, but by a disguised mailman. Their actions compromised the original user.
The patch addressed this situation by complicating and strengthening authentication between the two ends—the DCOM server and the client. It included the sophisticated DCOM authentication RPC_C_AUTHN_LEVEL_PKT_INTEGRITY.
This level of protection ensures that data transmitted between the client and the server is not modified and cannot be falsified even partially.
What is DCOM?
Just in case, let's mention what DCOM is. It's an advanced Microsoft technology for connecting software components of computers on a network.
Many people don't fully understand the complexity and the fact that not all events are recorded in the administration log of the same name and have no visible impact on our networks.
The technology's principle is a protocol for providing objects using remote RPC calls. After the patch was implemented, changes and a testing period were required to ensure that no one else could bypass the protection.
RPC is the core of the development and is needed so that using this client-server protocol, developers can call procedures on a remote or local network node.
Data array sorting and connection details occur behind the scenes, deep within RPC at the machine level. This allows programmers and administrators to connect directly to client applications and remote computers.
Testing
This technology and the new patch are great because they don't require developers to know or worry about the details of how exactly information is exchanged, how procedures are called, and what data is moved between points.
However, such simplification makes diagnostics difficult and it is unclear what associated changes this will bring to the overall network environment and the system as a whole.
Therefore, it's important to test your business systems and identify any unusual or even abnormal application behavior. Even routine failures should be carefully examined for their causes. It's also recommended to determine whether the processes within your systems are compatible with your partners' and suppliers' ability to integrate this new feature. Will they be able to modify their software if it involves this protocol?
Verification and protection
In 2022, you'll need to complete testing by deploying the existing initial updates in a clean environment and finally determine whether this update impacts your business processes. You'll need to determine whether connecting a DCOM server using the new strong authentication principle provides benefits or, conversely, complicates your processes.
Microsoft will soon be gradually rolling out new authentication levels. The first release, as mentioned above, was released last year, and users will be manually installing updates to registry keys from then on.
To have comprehensive protection, set the RequireIntegrityActivationAuthenticationLevel = 1 registry key on DCOM servers.
Please note that these updates protect the Windows DCOM client, but do not protect in non-Windows environments.
Deployment guide for clients and servers to understand the impact on your network:
What will affect
In the initial test versions, patchers observed that when enabling and activating the key on Hyper-V clusters from the console, the operation only occurred on the owner cluster node. The Microsoft Management Console failover console worked selectively, not as expected by default. Also, WMI connections from hosts to failed Hyper-V clusters resulted in failures and access errors.
The solution adopted was to use PowerShell to manage the system or the Administration Center itself.
Once activated, enhanced security cannot be disabled, so it's important to test all components now. Understanding the implications will ensure you don't miss out on necessary updates in the future.
The company implementing strong authentication aims to roll out the entire update in stages to minimize potential unpleasant moments.
Test these parameters to avoid any side effects.
With us you will receive a reliable and securehosting, cooldomain And SSL certificatefor your business.