A security alert published by the federal government addresses several critical vulnerabilities in the implementation of net time sync, a protocol used to synchronize clock settings over the Internet, that put countless servers at risk if administrators do not install a security update.
The remote code execution vulnerabilities exist in versions of the protocol prior to 4.2.8, according to a statement issued Friday by the ICS-CERT (Industrial Control Systems Cyber Emergency Response Team). In many cases, the vulnerabilities can be exploited remotely by hackers with even low-level skills.
“Exploitation of these vulnerabilities could allow an attacker to execute arbitrary code with the privileges of the [network time protocol daemon] process,” the advisory said. Code to exploit the vulnerability is publicly available. It is unclear what privileges NTP processes, but some experts believe they typically require root access. Even if these privileges are limited, it is not uncommon for hackers to combine exploits with privilege elevation attacks.
In January, researchers uncovered evidence that the NTP vulnerability was being used to launch denial-of-service attacks on gaming websites. Attackers used the widely used service to boost their own available bandwidth, a technique that hit targets with 100 gigabits of data per second.
The bugs were discovered by Google Security Team researchers Neel Mehta and Stephen Roettger , and the vulnerabilities were patched in version 4.2.8.

