AUTOMATED SOFTWARE DEPLOYMENT TOOLS IN WINDOWS INFRASTRUCTURE. SECURITY ISSUES
Abstract
This article presents an in-depth security analysis of the built-in Group Policy Software Installation (GPSI) mechanism used for centralized software deployment in Windows Active Directory environments. The research focuses on the practical assessment of security risks associated with the substitution of MSI installation packages stored in network shares under misconfigured access permissions. An isolated laboratory environment was deployed to simulate a typical corporate domain network segment, comprising a Windows Server 2025 domain controller and two Windows 10 Pro client workstations. A series of attack scenarios was conducted, demonstrating that when NTFS permissions are incorrectly configured — specifically, when the Authenticated Users group is granted Modify rights — a low-privileged domain user can successfully replace a legitimate MSI package with a malicious one and trigger its installation on all domain workstations. It was established that, in the absence of activated digital signature verification policies, client systems perform no integrity or authenticity checks on packages prior to installation, and standard event logging does not capture file substitution events. A second experimental phase validated two countermeasures: restricting NTFS permissions to Read-only and enabling mandatory digital signature verification policies. Both measures effectively blocked the described attack vector. The findings indicate that the primary risk stems not from architectural flaws in the GPSI protocol itself, but from configuration errors and the non-utilization of available platform-level security controls. Practical recommendations are formulated covering strict access control, mandatory MSI package signing, and enhanced file auditing on critical network shares.
Online viewer
References
- Брысин А.Н., Журавлева Ю.А., Котов И.Ю. Исследование базовых атак и компрометации доменной Windows-инфраструктуры // Прикаспийский журнал: управление и высокие технологии. – 2023. – № 2. – С. 45–53.
- Корякин В.Ю., Тищенко Э.В. Тестирование защиты инфраструктуры GPO на базе Windows Server: анализ уязвимостей и методов обхода групповых политик // Труды молодых ученых РГУ нефти и газа (НИУ) им. И.М. Губкина. – Москва : РГУ нефти и газа (НИУ) им. И.М. Губкина, 2025. – С. 1–10.
- Болотов А.С., Болотова Т.П. Файловая система NTFS: обзор версий, производительность // Вестник Томского государственного университета. Управление, вычислительная техника и информатика. – 2012. – № 3 (20). – С. 21–28.
- Николаенкова О.А., Серик А.А., Хагуш Р.Э. Настройки конфигурации безопасности в Windows // Молодой исследователь Дона. – 2023. – № 1 (40). – С. 78–83.
- Баранов А.Н. Повышение эффективности процессов администрирования компьютерных систем путем использования технологии групповых политик // Информационные технологии и системы : сб. науч. тр. – 2022. – С. 15–22.
- Николаев В.В. Особенности реализации домена с тонкими клиентами на базе Microsoft Windows Server 2012 R2 // Международный студенческий научный вестник / СибАК. – Орёл. – 2016. – № 4. – С. 112–115.
- Толганбаев Т.К. Доменные службы Active Directory и ядро сервера // Вестник магистратуры. – 2014. – № 11 (38). – С. 30–33. – ISSN 2223-4047.
- Уймин А.Г. Нормирование показателей при организации киберполигона по сетевым технологиям // Нефть и газ – 2024 : тезисы докладов 78-й Международной молодежной научной конференции. – Москва : РГУ нефти и газа (НИУ) им. И.М. Губкина, 2024. – С. 1253–1254.
License
Copyright (c) 2025 A. A. Kyazimov , A. A. Tereshonok (Authors)