Security News > 2021 > July > Microsoft Shares More Information on Protecting Systems Against PetitPotam Attacks

Microsoft has shared more information on how organizations can protect Windows domain controllers and other Windows servers against potential PetitPotam attacks.
PetitPotam is the name assigned to a vulnerability that can be exploited by an unauthenticated attacker to get a targeted server to connect to an arbitrary server and perform NTLM authentication.
A proof-of-concept exploitation tool was made available last week for PetitPotam by France-based security researcher Lionel Gilles, and the SANS Institute's Internet Storm Center has published a step-by-step description of the attack.
Microsoft published an advisory in response to the findings, describing PetitPotam as a "Classic NTLM Relay Attack" and pointing to previously provided mitigations.
The company's advisory confirms that information on PetitPotam is publicly available, but says it has not been exploited in attacks.
In a blog post published on Thursday, cybersecurity firm Malwarebytes described the PetitPotam attack and noted that it will be difficult to patch "Without breaking stuff" due to the fact that it abuses legitimate functionality.
News URL
Related news
- Hackers use FastHTTP in new high-speed Microsoft 365 password attacks (source)
- Microsoft fixes under-attack privilege-escalation holes in Hyper-V (source)
- Ransomware gangs pose as IT support in Microsoft Teams phishing attacks (source)
- Week in review: 48k Fortinet firewalls open to attack, attackers “vishing” orgs via Microsoft Teams (source)
- Microsoft Teams phishing attack alerts coming to everyone next month (source)
- CISA tags Microsoft .NET and Apache OFBiz bugs as exploited in attacks (source)
- Critical RCE bug in Microsoft Outlook now exploited in attacks (source)
- Microsoft Identifies 3,000 Leaked ASP.NET Keys Enabling Code Injection Attacks (source)
- Microsoft Uncovers Sandworm Subgroup's Global Cyber Attacks Spanning 15+ Countries (source)
- Microsoft: Hackers steal emails in device code phishing attacks (source)