Tuesday, May 17, 2022
News

Microsoft discovers undisclosed bug in SolarWinds server

   SocialTwist Tell-a-Friend    Print this Page   COMMENT

New Delhi | Saturday, 2022 6:15:07 PM IST
While monitoring threats related to a Java logging system called 'Apache log4j2', Microsoft researchers have discovered a previously undisclosed bug in the SolarWinds software that was compromised last year.

During the sustained monitoring of threats taking advantage of the 'Log4j2' vulnerabilities, the Microsoft Threat Intelligence Centre (MSTIC) team observed activity related to attacks being propagated via a previously undisclosed vulnerability in the SolarWinds 'Serv-U' software.

"We discovered that the vulnerability is an input validation vulnerability that could allow attackers to build a query given some input and send that query over the network without sanitation," Microsoft said in its security update.

SolarWinds said the Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitised.

"SolarWinds has updated the input mechanism to perform additional validation and sanitisation. No downstream affect has been detected as the LDAP servers ignored improper characters," the company said, adding that it affects 15.2.5 and previous versions.

Microsoft reported the discovery to SolarWinds and they immediately patched the vulnerability.

"SolarWinds has updated the input mechanism to perform additional validation and sanitisation. To ensure proper input validation is completed in all environments, SolarWinds recommends scheduling an update to the latest version of Serv-U," said the company.

Microsoft warned that the Russia-based cyber criminals, behind the massive SolarWinds software attack last year, are on the prowl again, this time targeting organisations integral to the global IT supply chain.

The Russian nation-state actor 'Nobelium' has targeted at least 140 resellers and technology service providers in global IT supply chains, it said.

--IANS na/sks/ksk/

( 269 Words)

2022-01-22-12:00:05 (IANS)

 
  LATEST COMMENTS ()
POST YOUR COMMENT
Comments Not Available
 
POST YOUR COMMENT
 
 
TRENDING TOPICS
 
 
CITY NEWS
MORE CITIES
 
 
 
MORE SCIENCE NEWS
Bezos' Blue origin targets May 20 for ne...
Here's how greenhouse gas emissions can ...
Study suggests some strategies to cut me...
Research suggests soil from moon can gen...
Scientists identify how brain triages em...
Research suggests a new approach to trea...
More...
 
INDIA WORLD ASIA
KTR takes a jibe at PM over 'Acche Din'...
Close aide of actor Dileep arrested in a...
12-year-old girl forcibly married to 35-...
CPI(M-L) wants Left unity in Bengal sans...
Rahul's jibe at regional parties critici...
Gyanvapi Masjid case: Shivling claim 'at...
More...    
 
 Top Stories
IISc and TalentSprint forge ahead i... 
SC directs ED to interrogate TMC le... 
Ramayana fame Ashok Vatika faces fi... 
IWL: Gokulam Kerala to lock horns a... 
Parcos announces its first Parcos S... 
Aryav showcase air water generator ... 
Taliban dissolve Human Rights Commi... 
'It happens only in India': Chirag ...