A Note From the Help Desk: Microsoft Windows Support Diagnostic Tool Vulnerability

ATTENTION ONLINE AND SELF-PROCESSING CREDIT UNIONS

Microsoft Windows Support Diagnostic Tool Vulnerability

What Is It?

CU*Answers Network Services is tracking a recently announced security vulnerability when the Microsoft Windows Support Diagnostic tool is used to execute arbitrary code with the privileges from another application such as Microsoft Word.

How Does It Work?

The primary method of executing this vulnerability is through email phishing attacks.  Bad actors will send an email attempting to dupe the recipient into opening or previewing an attachment with malicious content embedded in the file.  If the file is opened or accessed via the preview function, the attacker could install programs, view, change, delete data, or create new accounts in the context allowed by the user’s rights.

Successful exploitation of this vulnerability requires users to take an action on their computer, so training your users not to click on links, access attachments that are unexpected, or install software on their computers is your best first line of defense.

What Is Microsoft Doing About It?

Microsoft has released a workaround that disables built-in Windows functionality involving the Microsoft Support Diagnostic Tool.  This will break the ability to launch troubleshooting tools via links within the operating system.  Please refer to the Microsoft Security Response Center article for more details: Guidance for CVE-2022-30190 Microsoft Support Diagnostic Tool Vulnerability – Microsoft Security Response Center.

What Can You Do About It?

As mentioned, your best course of action is to educate and frequently remind your users not to fall victim to phishing attacks.  Do not let users operate with local administrator rights.  Keep your anti-virus software up to date, and use your firewall to restrict outbound access to the Internet to only those sites required to run your business.

Implementing Microsoft’s Mitigation Steps:

CNS can implement Microsoft’s documented workarounds on your network if requested by you, but we will not be making these changes proactively, due to the need to modify each computer’s registry settings as well as remove built-in Windows functionality of the Windows Explorer program.

If you would like to proceed with these workaround steps, please contact the Help Desk to open a ticket for this work.  In the ticket request, please reference “CVE-2022-30190 Mitigation Steps” so that we can track the work we will do on your network.

CNS will assess our normal hourly fee on a time and material basis for implementing Microsoft’s recommended mitigation steps and troubleshooting any issues that occur due to the implementation.  However, it is important that you communicate the reduced functionality with your staff prior to work being done.

 

If you have questions or concerns, please contact the Help Desk at extension 266, or by email.

Your Credit Union Has Questions, Our Teams are Here to Help!

Your Credit Union Has Questions, Our Teams are Here to Help!

At CU*Answers, we know how important it is that your Credit Union gets the appropriate help in order to meet your day-to-day data processing needs.  When you don’t know exactly who to contact, we recommend that you get started by reaching out to either the Client Services and Education Team or the Network Services Team…. Read more »

Apr 3, 2024

Need Assistance from Network Services? Submit a Request via ConnectWise!

Need Assistance from Network Services?  Submit a Request via ConnectWise!

If your credit union requires assistance from CU*Answers Network Services, please note that Network Services categories are no longer accessible through AnswerBook.  Instead, your credit union should reach out via ConnectWise with any requests directed to the Network Services team. Examples of common requests that can be submitted via ConnectWise include: Equipment troubleshooting/failure (workstations, printers,… Read more »

Jan 31, 2024

Updated Deployment Plan for IBM i Access Upgrades – Complete Yours by 5/1/2024

Updated Deployment Plan for IBM i Access Upgrades – Complete Yours by 5/1/2024

Earlier this winter, CU*Answers Network Services announced a temporary suspension of our deployment plans for IBM iAccess Upgrades.  We have since performed the necessary adjustments to our plans – your credit union can begin downloading the latest version (1.1.9.4) as of today, January 25th. Please note that this update is required for all CU*Answers clients,… Read more »

Jan 25, 2024

Your Credit Union Has Questions, Our Teams are Here to Help!

Your Credit Union Has Questions, Our Teams are Here to Help!

At CU*Answers, we know how important it is that your Credit Union gets the appropriate help in order to meet your day-to-day data processing needs.  When you don’t know exactly who to contact, we recommend that you get started by reaching out to either the Client Services and Education Team or the Network Services Team…. Read more »

Jan 11, 2024

IBM i Access Client Solution Deployment Suspended – New Deployment Plan Coming Soon

IBM i Access Client Solution Deployment Suspended – New Deployment Plan Coming Soon

Recently, CU*Answers delivered several announcements on required IBM i Access Upgrades for 2024.  Since the start of this communication series, CU*Answers has been working with our credit unions to upgrade IBM i Access Client software on your PCs. Unfortunately, on December 8, 2023, IBM disclosed three vulnerabilities (CVE-2023-45184, CVE-2023-45182, CVE-2023-45185) affecting this software.  As a… Read more »

Dec 13, 2023

Winter is Coming… and So are the Latest IBM iAccess Upgrades!

Winter is Coming… and So are the Latest IBM iAccess Upgrades!

Don’t forget: it’s time to upgrade IBM iAccess (used for print sessions) to 1.1.9.2!  This update is required for all CU*Answers clients, in order to keep workstations up to date with currently-supported software.  The updates will need to be applied to all of your CU*BASE workstations and must be completed by 1/31/2024. Your IT staff… Read more »

Nov 27, 2023

Don’t Fall Behind – Complete Your IBM iAccess Upgrades Today!

Don’t Fall Behind – Complete Your IBM iAccess Upgrades Today!

It’s time to upgrade IBM iAccess (used for print sessions) to 1.1.9.2 – this update is required for all CU*Answers clients, in order to keep workstations up to date with currently-supported software.  The updates will need to be applied to all of your CU*BASE workstations and must be completed by 1/31/2024. Your IT staff can… Read more »

Nov 13, 2023

Don’t Fall Behind – Complete Your IBM iAccess Upgrades Today!

Don’t Fall Behind – Complete Your IBM iAccess Upgrades Today!

It’s time to upgrade IBM iAccess (used for print sessions) to 1.1.9.2 – this update is required for all CU*Answers clients, in order to keep workstations up to date with currently-supported software.  The updates will need to be applied to all of your CU*BASE workstations and must be completed by 1/31/2024. Your IT staff can… Read more »

Oct 30, 2023