HomeSecurityMicrosoft fixes the problem in the Group Policy component

Microsoft fixes the problem in the Group Policy component

Group Policy

This month's Microsoft updates include a patch for a seriousGroup Policythat affects all computers and devices that are part of a corporate Active Directory. The risk extends to tens of millions of computing devices, since all versions of Windows are vulnerable.

The flaw has been named JASBUG, by researchers at JAS Global Advisors who, along with simMachines, a provider of solutions for Advance Analytics and ICANN, participated in the discovery of the vulnerability.

The discovery was made during an investigation by JAS into name conflicts in .com domains and other TLDs (top-level domains). The issue was reported to Microsoft in January 2014, and all parties agreed not to disclose it until a fix was released to correct the problem.

CVE-2015-0008, as the flaw was identified, could be exploited by a remote attacker to take full control of the system. They could install programs, modify or delete data, or create new accounts with full privileges. Researchers say the flaw has been hidden for at least ten years.

The management of a large number of computers can be done by administrators through controllers, servers that communicate with the machines via VPN or by connecting to the internet, then the local network. This is mainly done in corporate environments, where employees work with computers and corporate security standards.

Microsoft explains that the Group Policy component performs security downloads from Universal Naming Convention (UNC) and runs any scripts defined in Group Policy Objects (GPO).

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS