?
Solved

Ghost Vulnerability - Statement of Impact on a Windows Environment

Posted on 2015-02-20
2
Medium Priority
?
176 Views
Last Modified: 2015-03-05
Hi Guys

I have to produce a statement of impact for the Ghost Vulnerability in Windows Environment (no linux).

I realise this is primarily a Linux issue, but i am struggling to find any formal references to confirm how Windows is affected (..or not).

Also, is there any impact on the networking peripherals such as firewalls and Internet facing F5 load-balancers?

Could anyone please point me at some reputable reference resources?

Thanks


M
0
Comment
Question by:mk112233
2 Comments
 
LVL 25

Accepted Solution

by:
Zephyr ICT earned 2000 total points
ID: 40620898
I think you need to look at it more from an application point of view regarding Windows vulnerability <> Ghost.
For example, what applications are running on Windows that might be vulnerable and check out the statements the vendors made regarding Ghost and their applications. Thinking about Cisco or Juniper software clients for network protection or maybe VPN software clients...

Here is the Cisco page regarding their devices/software and this vulnerability

Here is a page I found listing some major vendors and the links to their report regarding the vulnerability, you'll see F5 is listed along with some other major vendors.

As far as I can tell there is no official Microsoft bulletin regarding CVE-2015-0235, might be I missed it though.
0
 
LVL 12

Expert Comment

by:andreas
ID: 40621355
Windows SHOULD not be affected in its core. But installed software might bring some components of glibc, may be even statical linked so its not easy to see. this could then pose the same risks as on linux ,even remote code execution.

Windows itself should not contain any glibc code, else microsoft should mention the lgpl licensed code somewhere.

for the network envoronment it depends on the operating system running on it. if it has a vulnerable glibc it might be vunerable like linux systems.
0

Featured Post

Become a Leader in Data Analytics

Gain the power to turn raw data into better business decisions and outcomes in your industry. Transform your career future by earning your MS in Data Analytics. WGU’s MSDA program curriculum features IT certifications from Oracle and SAS.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Sometimes Administrators rights are not enough. These cases call for the SYSTEM account. The process in this article outlines the steps required to execute commands using the SYSTEM account.
With the evolution of technology, we have finally reached a point where it is possible to have home automation features like having your thermostat turn up and door lock itself when you leave, as well as a complete home security system. This is a st…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question