Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Microsoft fixes remote desktop app Mac hole (MS Remote Desktop app for MacOS/OSX)
The Register ^ | Jan 24, 2017 | Darren Pauli

Posted on 01/23/2017 8:34:42 PM PST by dayglored

Full read/write access was there for the taking

Microsoft has patched a code execution hole in its Mac remote desktop client that grants read and write to home directories if users do no more than click a link, says Italian security researcher Filippo Cavallarin.

The hole was patched 17 January.

Cavallarin says the flaw allowed remote attackers to execute arbitrary code on vulnerable machines if users did not more than click phishing links.

From there, attackers would gain read and write access to Mac home directories.

"Microsoft Remote Desktop Client for Mac OS X allows a malicious terminal server to read and write any file in the home directory of the connecting user," Cavallarin says.

"The vulnerability exists to the way the application handles rdp urls. In the rdp url schema it's possible to specify a parameter that will make the user's home directory accessible to the server without any warning or confirmation request.

"If an attacker can trick a user to open a malicious rdp url, they can read and write any file within the victim's home directory."

Mac OS X apps like Safari, Mail, and Messages by default open clicked rdp urls without confirmation.

This drastically shortens the attack chain of most phishing attacks which require users to be convinced by some form of narrative to open links and attachments, and again to fill out personal data and credentials into fake forms.

Cavallarin included a proof-of-concept with his disclosure, increasing the need for users to apply the Microsoft updates.

[... video of the exploit at the article...]


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: macos; remotedesktop; windows; windowspinglist
I use this app all the time to access Windows machines remotely from my Mac. It's a great app, but this is one heckuva hole. Glad Microsoft patched it! Update time!!
1 posted on 01/23/2017 8:34:42 PM PST by dayglored
[ Post Reply | Private Reply | View Replies]

To: Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; amigatec; AppyPappy; arnoldc1; ATOMIC_PUNK; ...
Remote Desktop App for Mac -- time to update!! ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

2 posted on 01/23/2017 8:36:09 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Hey Swordmaker, this one is really for the Apple Ping List, since the app is a MacOS app, used to access Windows computers.


3 posted on 01/23/2017 8:37:08 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

BTW, going back in my Mac’s update history, I see that my installation of this app was updated in Jan 19 along with a few others. So it is getting pushed out with the regular Mac updates, if you have already installed the app previously.


4 posted on 01/23/2017 8:40:21 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 3 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson