Turning Enterprise Update Servers Into Backdoor Factories (0_o) – Part 1
ID: 53e744db-378f-5d7a-a1a7-4abdd7d427a8
STIX ID: report--53e744db-378f-5d7a-a1a7-4abdd7d427a8
Feed Name: SpecterOps Blog
Threat Score
This blog (part 1 of 2) documents research showing how, when WSUS uses an external MSSQL database, an attacker who can coerce the WSUS computer account to authenticate to the SQL server can leverage the webService role's execute-only permissions to call WSUS stored procedures and import, host, target, and deploy malicious updates to specific machines—effectively enabling targeted malware distribution and lateral movement via the update infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
