3 ms·
Does it still run as SYSTEM? If so, fix that and come back later please. https://bugs.chromium.org/p/project-zero/issues/detail?id=1282&desc=2 https://bugs.chr
by cjsuk 9y ago
Does it still run as SYSTEM? If so, fix that and come back later please.
https://bugs.chromium.org/p/project-zero/issues/detail?id=1282&desc=2 https://bugs.chromium.org/p/project-zero/issues/detail?id=12...
- ksk 9y agoCan you explain what you mean by "fix that"? How is that helpful? I read your link and it doesn't provide any actionable items. In any case, it doesn't "run as SYSTEM". The invoking credentials for a process are not necessarily relevant on a kernel like NT. A process can choose modify its security token after process invocation. For e.g. User mode apps, can downgrade their read/write rights, limiting them to a fixed directory, so even if they had exploitable bugs, the damage could be limited. Chrome on windows uses these same protections. I'm sure similar tech exists on competing kernels. MsMpEng.exe AFAICT runs as a 'system protected process'. Certainly, it looks like there were severe bugs but its not clear where the bugs lie. It could be that the protection mechanism itself is flawed (which would be very bad), or maybe the way it's being used is incorrect, etc etc
- Someone1234 9y agoDifferent poster... Certain parts of an AV product need to run with the top-most privileges. But that component should be relatively lean, and quickly hand off dangerous work to lower-privilege, memory isolated, processes. Windows Defender has a process called NScript which is a full JavaScript processing engine, running in SYSTEM. A JavaScript engine is inherently complicated enough to have bugs, and running as SYSTEM with no isolation could allow escalating a bug into a full blown code execution just by visiting a web page. None of this is theoretical, it was found and exploited May 2017 [0]. You're correct in saying that Windows does allow more nuanced token control than the full user's context, but I'm yet to read that Windows Defender actually utilises that. None of the previous bugs have been stopped by low-priv style access control, it has been a full SYSTEM leak. Do you have specific information about Windows Defender which suggests they're using voluntary revocation of token privileges? [0] https://bugs.chromium.org/p/project-zero/issues/detail?id=1252&desc=5 https://bugs.chromium.org/p/project-zero/issues/detail?id=12...
- ksk 9y ago>Do you have specific information about Windows Defender which suggests they're using voluntary revocation of token privileges? Sure, just dump the security token for MsMpEng.exe. Here it is: https://pastebin.com/ukMPUWA7 https://pastebin.com/ukMPUWA7 IntegrityLevelIndex is 01, MandatoryPolicy is 0x3 , Privs are a subset of the full list. https://www.nirsoft.net/kernel_struct/vista/TOKEN.html https://www.nirsoft.net/kernel_struct/vista/TOKEN.html https://msdn.microsoft.com/en-us/library/windows/desktop/bb530716(v=vs.85).aspx https://msdn.microsoft.com/en-us/library/windows/desktop/bb5... https://msdn.microsoft.com/en-us/library/windows/desktop/bb394728(v=vs.85).aspx https://msdn.microsoft.com/en-us/library/windows/desktop/bb3... https://msdn.microsoft.com/en-us/library/bb625963.aspx https://msdn.microsoft.com/en-us/library/bb625963.aspx
- youdontknowtho 9y agoYou effectively have to be able to debug other processes, copy data to and from a process, and a lot of other control. What would it run as that would have all those permissions?
- cjsuk 9y agoSorry I was being rather facetious there. They have VSM available (Application Guard). This is only on Enterprise edition because you know, only enterprises need a decent threat protection model...