pwshub.com

Design flaw could allow hackers to roll back Microsoft Windows updates

LAS VEGAS — Some of Microsoft’s most important tools for protecting Windows users from malicious hackers can be twisted into being used in attacks, according to research presented here Wednesday at the annual Black Hat security conference.

The newly discovered method includes altering the internal registry of a Windows machine to make it seem that it has been updated through Microsoft’s regular process for issuing improvements and security fixes.

That would allow an attacker to downgrade the machine to earlier versions of Windows, making hundreds of vulnerabilities that are patched in current versions of Windows fair game once more.

The technique fools another highly touted security innovation, known as virtualization-based security, by renaming a file folder, according to Alon Leviev, a researcher for security company SafeBreach who is presenting the findings at Black Hat and at Def Con, the hacking conference that begins here Friday.

Microsoft’s feature is supposed to stop any tainted core element of an operating system from working, but Leviev beat it, giving him complete control of test machines.

Microsoft said it was still working on mitigations for the attack technique, which Leviev reported to the company in February. It said it had no evidence that criminals or spies had been using the method in actual attacks, although that could change after Wednesday’s public presentation.

“We appreciate the work of SafeBreach in identifying and responsibly reporting this vulnerability,” said Microsoft spokesman Jeff Jones. “We are actively developing mitigations to protect against these risks.”

Because the security flaw is in the design of multiple Windows sub-programs, fixing it is not as simple as issuing a patch. Instead, Microsoft has to craft an update that revokes and replaces old system files. A wide variety of tests are needed to be sure the fix does not harm or crash Windows computers, Microsoft said.

Leviev said he began looking for ways to force Windows downgrades in the wake of a similar rollback attack demonstrated a year ago against Microsoft’s Secure Boot process for starting machines safely. He looked for other key programs that might be vulnerable to the same technique and found it in the update process.

He said one lesson from his work is that vendors and outside researchers should look carefully at new types of attacks to see if similar approaches would also work. In the past few years, outside researchers and some former Microsoft employees have complained that Microsoft patches only the exact vulnerabilities that friendly researchers demonstrate, instead of re-designting programs to eliminate entire classes of attacks.

Under fire for other security failings that allowed foreign spies to hijack the email accounts of top U.S. officials, Microsoft pledged this year to make security performance a part of salary reviews.

Source: washingtonpost.com

Related stories
1 month ago - A significant vulnerability in Microsoft Windows security tools was unveiled at the Black Hat security conference. Alon Leviev, a researcher from SafeBreach, showcased a method to exploit the Windows update process, enabling attackers to...
3 weeks ago - Microsoft applications can become a hacker’s paradise on Apple Macs due to an unpatched vulnerability, but Microsoft doesn’t consider it a big enough threat to fix.
1 month ago - Computer scientists brainstorm in Pentagon-backed competition to design an AI program that scans open-source code for flaws bad actors could exploit
1 week ago - It promised vanishing messages, but now 'it's privacy theater' Video  A popular privacy feature in WhatsApp is "completely broken and can be trivially bypassed," according to developers at cryptowallet startup Zengo.…
1 month ago - Kernel mode not good enough for you? Maybe you'll like SMM of this Some AMD processors dating back to 2006 have a security vulnerability that's a boon for particularly underhand malware and rogue insiders, though the chip designer is only...
Other stories
1 minute ago - Install the best shower head filter in your bathroom to protect both your hair and skin. These filters clear your water of impurities and contaminants for a better shower experience.
1 hour ago - As an Amazon Prime member, not only do you get a free Grubhub+ membership, you can also score $10 off your first $15 order.
1 hour ago - Amazon's second Prime Day event of 2024 is still a few weeks away, but there are some bargains you can score now.
1 hour ago - YouTube will roll out a new generative AI video tool named Veo later this year that'll allow creators to create 6-second clips with nothing more...
2 hours ago - FBI Director hails successful action but calls it “just one round in a much longer fight.”