Microsofts patch Tuesday reveals a patch for a shocking privilege escalation vulnerability, discovered by Preempt researchers.

The vulnerability exposes a flaw where LDAP fails to protect against NTLM relay attacks regardless of LDAP signing being enabled? LDAP signing was created to prevent this type of “Man in the middle” attack from forwarding credentials to a target server.

Currently the vulnerability allows an attacker with SYSTEM privileges to target incoming NTLM sessions to trigger LDAP operations such as updating domain objects in the context of the NTLM user.

An excellent video outlining the attack and how the same flaw can be combined with an rdpy to create a domain admin via “RDP Restricted admin mode”, this mode should protect against this type of attack however when rdpy is combined with the ldap relay vulnerability the video shows a domain admin account is created by downgrading the RDP restricted mode to NTLM.
However Microsoft have dismissed the RDPY issue as a bug by stating this is a known issue?

The following CVE has been assigned to this issue: CVE-2017-8563

Microsofts advice to this is:
Consider disabling NT Lan Manager or digitally sign all LDAP and SMB traffic.

