Microsoft

New PetitPotam Attack Hits Windows Domains

A team of security researchers from France has discovered an unrecoverable vulnerability that affects Windows domain controllers and other Windows servers. Microsoft has already published a workaround to mitigate the vulnerability.

A research team from France published a proof-of-concept that shows how vulnerable the domain controller is. It’s about a so-called NTLM relay attack called PetitPotam. This enables threat actors to take over a domain controller and thus an entire Windows domain. After the takeover, an attacker could execute any command and thus effectively take over the Windows domain.

NTLM is a protocol introduced by Microsoft around 30 years ago. Although it has long been known that this protocol has numerous design problems and thus security weaknesses, it is still widely used. There are several steps involved in an NTLM relay attack that exploit the design problems of the protocol. This is exactly what has happened now.

In a conversation with BleepingComputer about the new relay attack method, one of the security researchers said that he does not see the attacks as a security flaw in the strict sense: “In my opinion, this is not a vulnerability, but an abuse of a legitimate function.” The researcher emphasizes that the only way to defuse this technique is to disable NTLM authentication or to enable protection mechanisms such as SMB signing or LDAP signing. The vulnerability cannot be remedied and is activated by default in all Windows environments.

Taking advantage of attenuation

Microsoft has therefore already acted quickly. The security team has published instructions and explanations. It states, “Microsoft is aware of PetitPotam, which can potentially be used to attack Windows domain controllers or other Windows servers. PetitPotam is a classic NTLM relay attack, and Microsoft has seen many of these attacks before Mitigation options to protect customers are documented. “

Windows Server versions from 2008 to 2019 are affected. Users should use Microsoft’s instructions to protect themselves. 

Recent Posts

Navigating the Digital Frontier: How Mobile Proxy Infrastructure Empowers Modern Technology Journalism and Enterprise Data Mining

For tech analysts, software engineers, and digital journalists tracking real-time market shifts on platforms like…

4 hours ago

Decoupling Digital Identity: How Modern App Ecosystems Rely on Virtual Telecommunications Architecture

Modern mobile security models treat phone numbers as default digital passports, forcing tech consumers and…

4 hours ago

Top Extended Detection and Response Platforms for Large Enterprises: A Vendor Comparison Guide

Large enterprises have a lot of security data, but identifying the signals that truly matter…

5 hours ago

5 Lab Methods Scientists Use to Find What’s Really in Tap Water

A glass of tap water reveals little about its chemical makeup. Clear water may still…

1 day ago

Medical Technology Leadership Programs and Industry Collaborators: The Essential Resource Roundup

In today’s healthcare landscape, collaboration between academic programs and corporate leaders fuels both technological innovation…

2 days ago

Smartphone ban: Italy will soon pay for distracted pedestrians

Italy is cracking down on cell phone use in traffic and will soon be targeting…

2 days ago