Hiding in Plain Sight – Taking Control of Windows Patches

Tech 2 (718B) October 19, 2016 2:40 pm - 3:40 pm Feedback     

Bookmark and Share

Travis Smith

On the second Tuesday of every month, Windows administrators stand ready to deploy the swarm of patches issues by Microsoft addressing new vulnerabilities found on mission-critical systems.  Although this patch management routing may have system admins feeling overwhelmed, Patch Tuesdays are expected, allowing them to plan accordingly for the maintenance windows. But IT organizations are not the only ones on standby – these expected changes also grant attackers the opportunity to hide their malicious intent in an abundance of patches. This session will demonstrate how an attacker can exploit a gap in the information provided by Microsoft, in order to bypass security products intended to validate the integrity of patches on Windows systems. As part of this talk, free tools and resources to enable organizations to defend against such an attack will be made available.