HomeHow ToHow to avoid exploiting the new Windows Font Parsing Zero-Day vulnerability...

How to avoid exploiting the new Windows Font Parsing Zero-Day vulnerability via GPO

GPO

Microsoft Active Directory (AD) administrators can mitigate the impact of a newly disclosed zero-day vulnerability that allows remote code execution in the Windows Adobe Type Manager Library in large AD environments. Mitigation can be done using group policy (GPO).

Microsoft said on March 23 that it had detected some targeted attacks on devices running Windows 7 , attempting to exploit two unpatched vulnerabilities (one new and one older) in the Adobe Type Manager Library.

The vulnerabilities affect devices running desktop and server versions of Windows, including Windows 10, Windows 8.1, Windows 7, and multiple versions of Windows Server.

To exploit security issues , attackers trick victims into opening malicious documents or simply viewing them through the Windows Preview pane.

Microsoft has already provided some solutions to mitigate the risks posed by attacks using these vulnerabilities. Some of these solutions include disabling the Preview and Details panes in Windows Explorer , disabling the WebClient service , and renaming the vulnerable library (ATMFD.DLL).

However, Microsoft solutions are not easy to implement to mitigate attacks on an enterprise.

According to Sylvain Cortes, you can mitigate the problem with the help of group policy (Group Policy Object-GPO).

Using GPOs to mitigate risk in businesses

First of all, open the GPMC console and create a new GPO by right-clicking on the “Group Policy Objects”.

Next, go to: User Configuration>Policies>Administrative Templates>Windows Components>File Explorer and enable the two GPO options shown in the image below. This will disable the preview locally and across the entire network.

Windows

“Close the GPO and link this GPO to all user accounts in your organization”, added Sylvain.

Then, create a new GPO through GPMC and disable the WebClient service from Computer Configuration>Policies>Windows Settings>Security Settings>System Services.

This GPO must also be linked to all accounts in organization to disable WebClient everywhere.

Zero Day

Both GPOs should be rolled back when Microsoft releases an update to fix the font parsing zero-day vulnerabilities.

Microsoft said it is working on fixing the zero-day vulnerability and hinted that this will be done with the release of the new Patch Tuesday (on April 14).

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS