Vancouver, Surrey Indian Community - BCIndian.com
| | | | | | | | | | | |
 


 

Microsoft discovers undisclosed bug in SolarWinds server

Delhi,Technology

Author : Indo Asian News Service

Delhi, India, Technology Read Latest News and Articles

Share With Your Friends



Add an Article

View All Contributions

Add To My Favorite

Add A Picture

New Delhi, Jan 22 (IANS) While monitoring threats related to a Java logging system called 'Apache log4j2', Microsoft researchers have discovered a previously undisclosed bug in the SolarWinds software that was compromised last year.

During the sustained monitoring of threats taking advantage of the 'Log4j2' vulnerabilities, the Microsoft Threat Intelligence Centre (MSTIC) team observed activity related to attacks being propagated via a previously undisclosed vulnerability in the SolarWinds 'Serv-U' software.

"We discovered that the vulnerability is an input validation vulnerability that could allow attackers to build a query given some input and send that query over the network without sanitation," Microsoft said in its security update.

SolarWinds said the Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitised.

"SolarWinds has updated the input mechanism to perform additional validation and sanitisation. No downstream affect has been detected as the LDAP servers ignored improper characters," the company said, adding that it affects 15.2.5 and previous versions.

Microsoft reported the discovery to SolarWinds and they immediately patched the vulnerability.

"SolarWinds has updated the input mechanism to perform additional validation and sanitisation. To ensure proper input validation is completed in all environments, SolarWinds recommends scheduling an update to the latest version of Serv-U," said the company.

Microsoft warned that the Russia-based cyber criminals, behind the massive SolarWinds software attack last year, are on the prowl again, this time targeting organisations integral to the global IT supply chain.

The Russian nation-state actor 'Nobelium' has targeted at least 140 resellers and technology service providers in global IT supply chains, it said.

--IANS

na/sks/ksk/


Copyright and Disclaimer: All news and images appearing in our news section, search engines and social media are provided by IANS. If you face any issues related to the content/images, please contact our news service provider directly. We are not liable/responsible for any content/images related to the news service provider.


Latest News

View More News


More News Articles

IPL 2024: Mumbai Indians bat first against Rajasthan Royals in Hardik Pandya's 100th game

Allu Arjun, Jackie Shroff call for environmental conservation on Earth Day

IPL 2024: Mitchell Marsh to miss remainder of season due to hamstring injury

IPL 2024: Conversation with Kohli helped me during the bad phase, says RR's Riyan Parag

IPL 2024: Virat Kohli fined 50 percent match fee for dissent after dismissal in KKR match