{"id":2132,"date":"2012-03-26T10:49:11","date_gmt":"2012-03-26T14:49:11","guid":{"rendered":"https:\/\/www.bumc.bu.edu\/it\/?p=2132"},"modified":"2012-09-25T09:04:21","modified_gmt":"2012-09-25T13:04:21","slug":"security-alert-for-microsoft-windows-users-and-vpn-required-for-rdp","status":"publish","type":"post","link":"https:\/\/www.bumc.bu.edu\/it\/2012\/03\/26\/security-alert-for-microsoft-windows-users-and-vpn-required-for-rdp\/","title":{"rendered":"Security Alert for Microsoft Windows Users and VPN Required for RDP"},"content":{"rendered":"<h3><em>(View the<\/em><strong><em> original post from IS&amp;T\u00a0<a href=\"http:\/\/www.bu.edu\/tech\/2012\/03\/22\/security-alert-for-microsoft-windows-users\/\">here<\/a>)<\/em><\/strong><\/h3>\n<h3><strong>Summary<\/strong><\/h3>\n<h4><strong>Action Required for all Microsoft Windows Users:<\/strong><\/h4>\n<p><strong> <\/strong><\/p>\n<ol>\n<li>If you are running Microsoft Windows and you do not have it set to Automatically Update, you should run Windows Update immediately.\u00a0 See instructions at\u00a0<a href=\"http:\/\/www.bu.edu\/tech\/2012\/03\/22\/desktop\/virus-protection-security\/safe-computing\/autoupdate\/\">www.bu.edu\/tech\/desktop\/virus-protection-security\/safe-computing\/autoupdate\/<\/a> and confirm that you have the correct patches using the instructions below on this page.<\/li>\n<li><strong>If you\u00a0<em>do <\/em>have Automatic Updates turned on, you should have received the patch last Tuesday and you are all set \u2013 no further action is required toward installing it. <\/strong>You can confirm that you are updating automatically by following the instructions at\u00a0<a href=\"http:\/\/www.bu.edu\/tech\/desktop\/virus-protection-security\/safe-computing\/autoupdate\/\">www.bu.edu\/tech\/desktop\/virus-protection-security\/safe-computing\/autoupdate\/<\/a>.<strong> <\/strong><\/li>\n<li>If you use Microsoft Windows Remote Desktop (RDP) to connect to a BU computer from outside of BU,\u00a0<strong>you will need to connect to the VPN prior to connecting via RDP \u2013 login at\u00a0<a href=\"http:\/\/vpn.bu.edu\/\">http:\/\/vpn.bu.edu<\/a>.<\/strong><\/li>\n<li>If you have set up your system to allow remote access, or if you run a server, see the additional instructions below.<\/li>\n<\/ol>\n<h3><strong>Details<\/strong><\/h3>\n<p><strong> <\/strong><\/p>\n<h4><strong>The Problem:<\/strong><\/h4>\n<p>On Tuesday, March 13, Microsoft announced that a critical vulnerability had been discovered in all versions of Windows from XP and up.\u00a0 This vulnerability affects the Remote Desktop (RDP) feature of Windows.\u00a0 RDP allows a remote user to connect to the computer and the vulnerability may allow even an unauthorized person to do so.<\/p>\n<h4><strong>The Impact:<\/strong><\/h4>\n<p>An exploit has already been released that will cause a Blue Screen of Death on Windows 7 and a Denial of Service on Windows XP.\u00a0 It is expected that another exploit will soon be released that will allow an attacker to have complete control of the computer.\u00a0 After that, the next expected step is that a self-replicating worm will be released that will automatically jump from host to host, granting the attacker access to the system and taking any other action the attacker may wish.<\/p>\n<h4><strong>The Solution:<\/strong><\/h4>\n<p>Microsoft has released a patch for this vulnerability.\u00a0 See below for details on installing it.<\/p>\n<h4><strong>What IS&amp;T and the IT Partners are doing:<\/strong><\/h4>\n<ul>\n<li>IS&amp;T and the IT Partners have been working to install this patch on the servers at BU.<\/li>\n<li>Due to the serious nature of this vulnerability, IS&amp;T will be blocking RDP access at the BU firewall within the next few days. This block is necessary because it is common for people to disable the automatic update functionality.\u00a0 It can reasonably be expected that many systems will remain unpatched for an extended period of time.\u00a0 If we take no action to block access to RDP through the firewall, exploit code could significantly impact the stable operation of computers at BU or otherwise compromise BU operations or protected information.\u00a0 (For reference, as of Monday (3\/19) there were over 3000 computers at BU that had RDP up and operating.)<\/li>\n<\/ul>\n<h3><strong>Related Instructions<\/strong><\/h3>\n<h4><strong>If you never use RDP\u2026:<\/strong><\/h4>\n<ul>\n<li>If you do not need to use RDP, you can disable it. \u00a0Instructions are provided below.<\/li>\n<li>If you do need to use RDP, please follow the security best practices published by IS&amp;T:<br \/>\n<a href=\"http:\/\/www.bu.edu\/tech\/2012\/03\/22\/security\/protect\/bestpractice\/remote-desktop\/\">http:\/\/www.bu.edu\/tech\/security\/protect\/bestpractice\/remote-desktop\/<\/a><br \/>\nBest practices include moving RDP away from its standard port to some other port protected by the\u00a0<a href=\"http:\/\/www.bu.edu\/tech\/2012\/03\/22\/security\/firewalls\/campus\/\">BU Edge Firewall<\/a>.<\/li>\n<\/ul>\n<h4><strong>If you are running a server:<\/strong><\/h4>\n<ul>\n<li>Patch information can be found here:\u00a0<a href=\"http:\/\/technet.microsoft.com\/en-us\/security\/bulletin\/ms12-020\" target=\"_blank\">http:\/\/technet.microsoft.com\/en-us\/security\/bulletin\/ms12-020<\/a><\/li>\n<li>If the system cannot be immediately patched, please see this page for an alternative \u201cfix it\u201d option:<a href=\"http:\/\/blogs.technet.com\/b\/srd\/archive\/2012\/03\/13\/cve-2012-0002-a-closer-look-at-ms12-020-s-critical-issue.aspx\">http:\/\/blogs.technet.com\/b\/srd\/archive\/2012\/03\/13\/cve-2012-0002-a-closer-look-at-ms12-020-s-critical-issue.aspx<\/a><\/li>\n<\/ul>\n<h4><strong>Confirm that you have the correct patches:<\/strong><\/h4>\n<h5><strong>Windows 7<\/strong><\/h5>\n<p>1.\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Go to\u00a0<strong>Start<\/strong> -&gt;\u00a0<strong>All Programs<\/strong> -&gt;\u00a0<strong>Windows Update<\/strong> -&gt;\u00a0<strong>View Update History<\/strong> and confirm that KB2667402 and KB2621440 are installed<\/p>\n<p><a href=\"http:\/\/www.bu.edu\/tech\/files\/2012\/03\/image002.jpg\"><img loading=\"lazy\" title=\"image002\" src=\"http:\/\/www.bu.edu\/tech\/files\/2012\/03\/image002.jpg\" alt=\"image002\" width=\"433\" height=\"246\" \/><\/a><\/p>\n<h5><strong>Windows XP<\/strong><\/h5>\n<ol>\n<li>Go to\u00a0<strong>Start<\/strong> -&gt;\u00a0<strong>Microsoft Update<\/strong> -&gt;\u00a0<strong>Review your update history<\/strong><\/li>\n<li>Confirm that KB2621440 is installed<\/li>\n<\/ol>\n<p><strong> <\/strong><\/p>\n<p><strong> <\/strong><\/p>\n<p><strong> <\/strong><\/p>\n<h4><strong>How to disable RDP if you don\u2019t use it:<\/strong><\/h4>\n<h5><strong>Windows 7<\/strong><\/h5>\n<ol>\n<li>Go to\u00a0<strong>Control Panel<\/strong>, click\u00a0<strong>System And Security<\/strong>, and then click\u00a0<strong>System<\/strong>.<\/li>\n<li>On the System page, click\u00a0<strong>Remote Settings <\/strong>in the left pane. This opens the System Properties dialog box to the<strong>Remote<\/strong> tab.<\/li>\n<li>To disable Remote Desktop, select\u00a0<strong>Don\u2019t Allow Connections To This Computer<\/strong>,<\/li>\n<li>Also\u00a0<em>uncheck<\/em> the\u00a0\u00a0<strong>Allow Remote Assistance box<\/strong> as shown below and then click\u00a0<strong>OK<\/strong><\/li>\n<\/ol>\n<p><a href=\"http:\/\/www.bu.edu\/tech\/files\/2012\/03\/image006.jpg\"><img loading=\"lazy\" title=\"image006\" src=\"http:\/\/www.bu.edu\/tech\/files\/2012\/03\/image006.jpg\" alt=\"image006\" width=\"299\" height=\"333\" \/><\/a><\/p>\n<h5><strong>Windows XP<\/strong><\/h5>\n<ol>\n<li>Click\u00a0<strong>System<\/strong> in Control Panel.<\/li>\n<li>On the\u00a0<strong>Remote<\/strong> tab, clear the\u00a0<strong>Allow users to connect remotely to your computer<\/strong> check box, and then click\u00a0<strong>OK<\/strong>.<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>(View the original post from IS&amp;T\u00a0here) Summary Action Required for all Microsoft Windows Users: If you are running Microsoft Windows and you do not have it set to Automatically Update, you should run Windows Update immediately.\u00a0 See instructions at\u00a0www.bu.edu\/tech\/desktop\/virus-protection-security\/safe-computing\/autoupdate\/ and confirm that you have the correct patches using the instructions below on this page. If [&hellip;]<\/p>\n","protected":false},"author":5559,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[14,4],"tags":[],"_links":{"self":[{"href":"https:\/\/www.bumc.bu.edu\/it\/wp-json\/wp\/v2\/posts\/2132"}],"collection":[{"href":"https:\/\/www.bumc.bu.edu\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bumc.bu.edu\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bumc.bu.edu\/it\/wp-json\/wp\/v2\/users\/5559"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bumc.bu.edu\/it\/wp-json\/wp\/v2\/comments?post=2132"}],"version-history":[{"count":6,"href":"https:\/\/www.bumc.bu.edu\/it\/wp-json\/wp\/v2\/posts\/2132\/revisions"}],"predecessor-version":[{"id":4381,"href":"https:\/\/www.bumc.bu.edu\/it\/wp-json\/wp\/v2\/posts\/2132\/revisions\/4381"}],"wp:attachment":[{"href":"https:\/\/www.bumc.bu.edu\/it\/wp-json\/wp\/v2\/media?parent=2132"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bumc.bu.edu\/it\/wp-json\/wp\/v2\/categories?post=2132"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bumc.bu.edu\/it\/wp-json\/wp\/v2\/tags?post=2132"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}