20 ms·
Windows 10 in-place upgrades are a severe security risk
- gnu8 10y agoSounds like a case of 'already behind the airtight hatch'. If you have administrative privileges to install an OS upgrade then you have administrative privileges to disable filesystem encryption. On the other hand, if MS pushes the update to the PC and it self-launches or can be initiated by a non-administrator, then it seems like there is a real security problem here.
- johnnyo 10y agoArent these kinds of updates pushed out my Central IT? Just because they can push it out, there are still a lot of employees watching the update run that probably don't have admin access.
- derefr 10y agoAnother common Raymond Chen reminder: "Local Administrator != Domain Administrator". If a user gains administrative privileges on their own machine as part of a corporate network, that just means they can bork their own machine and IT will have to come and take it for repair (and they'll likely be disciplined for doing stupid things against IT policy.) If becoming a local administrator on your own machine allows you more privileges on the network, there's something wrong with the network's security architecture. (After all, in a regular, healthy corporate network, Bring-Your-Own-Machine scenarios—where everyone is their own local administrator—are common without posing any threat.)
- cm2187 10y agoAssuming all machines on the network do not have the same local admin password.
- Nullabillity 10y agoThis is a privilege escalation bug that lets you reset the admin password, but it doesn't give you the old password.
- cmdrfred 10y agoYou might be able to get the hash via mimikatz.
- sammydavis 10y agoI want to block my young teen-aged son from hacking into his time-locked win 7 (soon win 10). He already searched the web and found some kind of system restore scheme to reset his password. Next step was to encrypt the hard drive to block rebooting without password.
- tokenizerrr 10y agoThis was the case in my high school. The domain administrator account had the same password as well. Good times.
- deleted 10y ago[deleted]
- x0x0 10y agoI think the point is that bitlocker means that a locked machine shouldn't be accessible to anyone even at the keyboard who doesn't know the password. If that machine happens to be executing an upgrade, even a scheduled upgrade, this is a bitlocker security bypass.
- prodigal_erik 10y agoIt sounds like a machine running the upgrade can't be screen locked, which means you can't safely, e.g., use the restroom until it's finished.
- yread 10y agoIt's not earth shattering - somebody could steal a encrypted laptop that's already running and keep it running until an upgrade comes and then bypass bitlocker. Aren't there other ways of bypassing it with a running machine?
- hobarrera 10y ago> Aren't there other ways of bypassing it with a running machine? The key element here is that you don't need to be a local admin, just a regular user who has restart permissions.
- drzaiusapelord 10y agoMaybe with a home system, but in business most users don't have local admin rights but the systems are set to allow them to initiate updates, or updates happen the next time the computer boots up from patch tuesday. If an end-user catches an image-based update being deployed, she can just press that hotkey combo and get local admin rights. Scary stuff here for sysadmins until this is patched or some work-around can be implemented. WindowsPE is a whole separate Windows distro and has all its failings and security issues. MS doesn't seem to have hardened it correctly for its update system. This is also why organizations are usually 2-3 years behind Windows versions. Its just too risky to trust MS to get things done on an acceptable level without nearly 3 years of bug squashing and security auditing per Windows version. I've kept my employer on 7 until next year for reasons like these. Considering all the update and security issues with Win10, we might even put this off until 2018.
- Someone1234 10y agoIn the video they demonstrated that they're NOT local admin. The machine was set to automatically install updates, all they had to do was hit the "restart" button to start the automatic installation. They were then able to use a key combination to give them SYSTEM level access from a normal user account. This is absolutely an elevation exploit, and the fact it bypasses Bitlocker during in-place upgrade is a little disturbing. This bug likely isn't impactful for home users, but for enterprise-style systems (in particular in education) it has a big impact. Now every regular user can trivially become a local admin user. Problematic.
- ams6110 10y ago> Stick to LTSB version Good advice in general for almost any software.
- gkafkg8y8 10y agoAlthough I think it's strange what they exclude. For example, they didn't include Calculator in Windows Server 2016 LTSB: http://www.zdnet.com/article/windows-server-2016-ltsb-whats-in-and-whats-out/ http://www.zdnet.com/article/windows-server-2016-ltsb-whats-... Sure, maybe you wouldn't use it that much, but it's small and useful.
- JonathonW 10y agoThe Windows 10 Calculator is a Store app, and Server 2016 LTSB doesn't include Store apps. Therefore, Server 2016 LTSB doesn't have Calculator. While I guess they could bundle the Windows 7/8 Calculator with Server 2016, that would make server and desktop Windows different (for a feature that both include).
- userbinator 10y agoWhile I guess they could bundle the Windows 7/8 Calculator with Server 2016, that would make server and desktop Windows different (for a feature that both include). To make another guess, a lot of Server/LTSB users might actually like an even older Calculator: https://news.ycombinator.com/item?id=10791667 https://news.ycombinator.com/item?id=10791667
- mtgx 10y agoThey don't even include the Edge browser on Windows 10 LTSB. That's ... strange. Edge has been out for like 18 months on Windows 10. They really seem to have taken out the whole UWP platform on LTSB, so we once again see that the whole "one Windows to rule them all" spiel is nothing but a nice marketing story Microsoft likes to tell its fans, but not as real as they might like it to be. Unfortunately this just means Internet Explorer will have to be supported that much longer by developers. https://redmondmag.com/articles/2015/06/09/edge-windows-10-service-options.aspx https://redmondmag.com/articles/2015/06/09/edge-windows-10-s... http://www.techradar.com/news/software/microsoft-edge-s-enterprise-absence-may-lead-to-windows-10-fragmentation-1296280 http://www.techradar.com/news/software/microsoft-edge-s-ente...
- saipenguin 10y agoTo really be considered white hat wouldn't you have to wait until the fix is deployed?
- Shank 10y agoThat's exactly how responsible disclosure works. You wait until after the patch, then you do the blog post. In that order. Publishing early just damages your relationship with the company, the community, and makes it more well known that you _don't_ have good intentions.
- zyx321 10y agoIn this case the next time the vulnerability will be available is with the release of the next upgrade, expected around March.
- WorldMaker 10y agoInsiders see this style of Upgrade on a regular basis (with each new major Insider Build). Microsoft just made a big blog post about a new system for this style of Upgrade (the "Universal Patch Platform") and has asked Insiders to keep an eye out on it. A White Hat attempting responsible disclosure could at least check on Insider Builds and attempt to provide feedback on the new platform through official channels.
- zyx321 10y agoThe last Insider Fast build was 2 weeks ago. Maybe MSFT is holding the net one back until they fix this...?
- devoply 10y agoCome join Linux my friends. My fedora hat wearing greybeards wait for you. Only operating system left that gives semblance of privacy and security. And to those who think I am derailing... http://news.softpedia.com/news/microsoft-wants-all-linux-developers-to-move-to-windows-10-510551.shtml http://news.softpedia.com/news/microsoft-wants-all-linux-dev...
- renownedmedia 10y agoFedora is too young for Greybeards.
- leoc 10y agoAnd there's no active VAX port of Fedora anyway.
- sdegutis 10y agoIn all seriousness, why is Fedora the mosts worthy Linux out of them all, in terms of privacy and security? I thought those two were kind of an inherent staple of all Linux distros? In the past I've used Debian Stable with AwesomeWM (the inspiration for Mjolnir) and it felt pretty secure?
- devoply 10y agoI meant the hat not the distro. I use Ubuntu, I am happy with it. Before that used Debian and Slackware. Was happy with those too. Used it for 15 years. Can't complain. I don't feel my computing has been hurt by using Linux. And over time it seems as it's the only sane choice.
- 3131s 10y agoI misread your post too, but now it's clear on a reread that you meant the hat! I am also a proud and happy Linux user going on about 10 years now, and what's great is that I know all the knowledge I've acquired will still be relevant many decades into the future -- not sure the same can be said of Windows or MacOS.
- alien3d 10y agoI'm disable windows update and windows background intelligent service . The most reason was windows keep re downloading broken update and cost a lot my broadband bandwidth. To secure my laptop, i only remove csript.exe and wscript.exe.
- mappu 10y ago>i only remove csript.exe and wscript.exe. You are no longer running Windows, you are running alien3d's-special-snowflake-version. Please don't be surprised when many third party programs/games no longer run, because, some of my software certainly won't.
- eco 10y agoWe are dealing with this right now with our software. Our end users on Windows 7 who haven't kept their machine up to date can't install the VC++ 2015 redistributable which is required to run our software. It's a Microsoft problem but it's still frustrating having to do basic tech support for them just because they won't let Windows do the updates that it is insistently but politely asking them to let it do. Not a problem with our Windows 10 end users, of course.
- fghgfdfg 10y agoThese days I don't blame them. I'm guilty of it myself. After Microsoft repeatedly dropped in the Windows 10 "updates" (including nag) under new names it got to be enough of a hassle to avoid them that I've basically stopped updating. Finding the latest update names to ignore, then actually finding them in the update listing is enough of a pain to get me to continually put it off.
- razakel 10y ago>These days I don't blame them. I'm guilty of it myself. After Microsoft repeatedly dropped in the Windows 10 "updates" (including nag) under new names it got to be enough of a hassle to avoid them that I've basically stopped updating. My PC is next to my bed. I love being woken up at 3 in the morning by Windows attempting and failing to install updates. It's got to the point where I turn it off at the power supply to stop it.
- satysin 10y agoTL;DR When you do an in-place upgrade it does so in the SYSTEM authority. If you hit Shift+F10 during part of this process you get a Command Prompt running as SYSTEM. Then you can do some file system and registry changes to replace an accessibility feature exe with cmd and again run it under the SYSTEM authority pre-login and add your account to the Administrators group.
- Tepix 10y agoThat's not the bad part. The bad part is that this process suspends the disk encryption. Without disk encryption having physical access to the machine would be enough to elevate priviledges anyway.
- satysin 10y agoYes but that is documented as part of any in-place system upgrade or firmware upgrade https://technet.microsoft.com/en-us/library/jj649830.aspx https://technet.microsoft.com/en-us/library/jj649830.aspx
- 0xfeba 10y agoI knew I wasn't dreaming when my Bitlocked Win10 machine did the Anniversary Update and rebooted to the update screen without entering my Bitlocker password. Scary. But that must have been Windows PE doing the update.
- donatj 10y agoIs there not a presumption that with physical access to a machine it can be rooted if you try hard enough? I certainly make that presumption. The number of Macs I've unlocked by creating a new admin by removing the "install is finished" file in single user mode is in the teens.
- marcoperaza 10y agoIf you have Bitlocker setup with TPM and PIN, you should be secure even from attackers with physical access.
- semi-extrinsic 10y agoNot if you're still on Win7, like most corporations still mostly are: https://github.com/carmaa/inception/blob/master/README.md https://github.com/carmaa/inception/blob/master/README.md
- Godel_unicode 10y agoThis requires FireWire or thunderbolt, which is relatively uncommon on Windows machines.
- semi-extrinsic 10y agoAu contraire, mini-Firewire has been quite common on business laptops, which are the most common use case for BitLocker.
- marklgr 10y ago> The number of Macs I've unlocked by creating a new admin by removing the "install is finished" file in single user mode is in the teens. What's the procedure, in case I need to unlock a mac someday?
- zyx321 10y agohttp://apple.stackexchange.com/questions/164331/i-dont-have-administrator-account-on-my-mac http://apple.stackexchange.com/questions/164331/i-dont-have-... Won't work on an encrypted system, of course.
- aq3cn 10y agoWhat's the fix of it? There must be an option to stop full automation of upgrade process or MS can just recommend disconnecting from network while upgrade is taking place. MS does it for connivence I assume, so people aren't promoted while upgrade is taking place. This is my presumption, I may be wrong.
- wz1000 10y agoI don't know whether this works in newer versions of Windows, but it was extremely simple to elevate your priveleges on almost any Windows 7 machine. I've done this dozens of times. I haven't used Windows for years now, so the details are a bit fuzzy, but it essentially worked like this: Start the machine. During boot(when you see the orb splashscreen), turn off power or hold down the power button for a few seconds. The next time you boot up the machine, windows will say it failed to boot and offer to go into startup repair. Do that, wait for some time, and click through until eventually you see a bug report that you can open up in notepad. Once you are in notepad, open up the "open file" dialog. From there, navigate to "C:\Windows\System32" and replace "sethc.exe" with "cmd.exe". Now, reboot normally. Once you reach the login screen, spam left shift until you get a command prompt with admin privileges. Now, you can create new users, change the password and privileges of existing users, or even start up explorer.exe and use the computer normally as admin, bypassing the login screen entirely. This works because "sethc.exe" is the executable responsible for Sticky Keys, which is activated by pressing shift repeatedly. Instead of sethc.exe, now cmd.exe would be run instead.
- AaronFriel 10y agoOn BitLocker protected machines, you would need to provide the recovery key to unlock the disk and open any file. Edit: To clarify why that isn't the case here, the Windows 10 upgrade process suspends BitLocker.
- developer2 10y agoYou're kidding, right? You can drop in any executable in place of sticky keys? And it runs with Administrator privileges? How does Microsoft own the enterprise and government spaces with glaring lack of basic security like this? :/
- Nullabillity 10y agoYup. You can also drop in any executable in place of the "accessibility center" which, of course, also runs as admin in the login/lock screens.
- 10y ago
- cm2187 10y agohttps://blogs.windows.com/business/2016/11/11/defending-against-ransomware-with-windows-10-anniversary-update/#j1k5ggD9MjFF4GzK.97 https://blogs.windows.com/business/2016/11/11/defending-agai... > Combined with other significant security advances, such as Credential Guard, Windows Hello and others, we’ve made Windows 10 Anniversary Update the most secure Windows ever.
- kagamine 10y agoAll this and the comments assume Windows will let you upgrade at all. Google "windows 10 upgrade something happened" and then try to find the fix for that amazing piece of error reporting. In my case it was either that the language pack was wrong: Eng UK not Eng US, neither of which actually have language pack installed... or it was the Win toobar/menubar being docked to the left of the screen and not the bottom. One of these stopped the upgrade completely, repeatedly. The greatest security risk had to be getting stuck on an old version of Windows with no good info on how to fix a 2 year old bug in the upgrade process.
- jbarberu 10y agoSo, you leave your machine with BitLocker unlocked and unattended and people can gain admin privileges? I don't see how anyone would expect their data to be secured by disk encryption of the machine isn't powered down. Or am I missing something?
- Cthulhu_ 10y agoWindows 10's updates can also start while the computer is locked though.
- alkonaut 10y agoI don't understand either (didn't watch video though). Is the problem that the machine can be locked and still start the upgrade process, during which a non admin at the keyboard can rrad the disk? That would be a pretty serious hole but would be easily fixable by only starting updates when unlocked.
- zerohm 10y agoLet's say you are a desktop admin updating 500 Windows 10 machines. Maybe some of these machines are terminals for customers. This bug is a significant attack vector to gain admin on those machines being updated.
- excalibur 10y agoAnyone want to start a pool on how long it will take for an announcement that this also applies to Server 2016?