Table of contents exchange of letters with the minister executive summary


Versions of Outlook used by IHiS were not patched against ab bpublicly available hacking tool



Download 5.91 Mb.
View original pdf
Page75/329
Date27.11.2023
Size5.91 Mb.
#62728
1   ...   71   72   73   74   75   76   77   78   ...   329
Report of the COI into the Cyber Attack on SingHealth 10 Jan 2019
15.5 Versions of Outlook used by IHiS were not patched against ab bpublicly available hacking tool
251. A publicly available hacking tool played an important role in the compromise of Workstation A (see section 14.2 (pg 54) above. The attacker was able to install the hacking tool on Workstation A on 1 December 2017 by exploiting a vulnerability in the version of the Outlook application installed on the workstation.



COI Report – Part III
Page 86 of 425

252. A patch that was effective in preventing the vulnerability from being exploited (and thus to prevent the installation of the tool) was available since late. Leong Seng has explained that software security patches are applied on SingHealth and IHiS issued endpoints based on a specified posting cycle, except for critical patches addressing serious vulnerabilities, which would be applied as soon as possible. The patch was scheduled to be rolled out as part of
IHiS’ regular patching cycle, but the patch had not been applied to Outlook on Workstation A as at 1 December 2017.
253. Counsel for IHiS has submitted that IHiS’ conduct in respect of the patching cycle for Outlook was “reasonable”, and that it was “entirely fortuitous” for the attacker to have executed the hacking tool within the period between the release of the patch and its application. Once again, the reasonableness of IHiS’ conduct in this respect is not in issue. What the Committee is concerned with, and has found, is that the hacking tool was installed on Workstation A by exploiting a vulnerability on Outlook, that a patch was available since late but was not applied at the time the hacking tool was installed on 1 December
2017, and that the patch was scheduled to be rolled out as part of the regular patching cycle. The Committee’s recommendations on improving software upgrade policies are found in section 47 (pg 381) below.

Download 5.91 Mb.

Share with your friends:
1   ...   71   72   73   74   75   76   77   78   ...   329




The database is protected by copyright ©ininet.org 2024
send message

    Main page