12 ms·
Windows 7 patch for Meltdown enabled arbitrary reads and writes in kernel memory
- avhon1 9y agoThe article says that this vulnerability was patched in March 2018, so at least there's that.
- gerdesj 9y agoI'm still working on a bloody huge list of customer updatathons for Meltdown and Speccy. Now I have to go back around a load of them that I have already patched and find the Win 7s and 2008r2s and update those before I continue. Oh well, it gives me something to do of an evening 8)
- Someone1234 9y agoWhy are you manually patching workstations? WSUS allows central management (inc. zone deployment), but even in Windows 7's default state it should apply these updates without intervention. 2008R2 I can see doing it by hand, but Windows 7 clients is odd. Particularly as it seems to be taking you two months to apply urgent patches.
- gerdesj 9y agoSome of my customer VMs are Windows 7 - Veeam proxies for example. I also take backups quite seriously. Yes this is all a bit manual in some cases. (Nearly) All of them are on the end of an IPSEC VPN that I can get at from home via the office web proxy and another VPN or via magic. Some of them have 192.168.0/24 or 192.168.1.0/24 - those are on the end of OpenVPN. I wrote this: https://doc.pfsense.org/index.php/OpenVPN_NAT_subnets_with_same_IP_range https://doc.pfsense.org/index.php/OpenVPN_NAT_subnets_with_s... . You have no idea what networking is about until you've had to do that sort of nonsense a few times 8) I don't have the luxury of one WSUS to manage, we have loads of the bloody things. Some customers have pretty skilled local IT depts, some have somewhat vocal users that accuse you of resetting their passwords after spending hours doing way more than they have paid for and would not understand what you are on about in the first place. I love them all equally as any parent would ... When I get bored of watching Windows Update I run apt update && apt upgrade && reboot on a few machines and keep a weather eye on the monitoring system. When I get really bored, I run up yaourt on my laptop or my office PC. When I've got a newly installed Win system or two to patch, I fire up a few emerge -Uvh --deep --newuse --keep-going @world sessions (I'm not really joking here) or run up genkernel. Yes, there is the default state designed by .... bbzzzzrrt .... soz, lost it, and then there is reality. Could I also remind you that there is rather more to patching than WSUS: * Firmware - Dell, HPE and Co have had to do rather a lot of work here and had to start again in Jan when Intel dropped the ball * Hypervisors - I generally see VMware - that's a lot of patching and don't forget that some of them were buggered, so need excluding. * VM vHardware versions - yep, all those little lovelies have their own hardware types to worry about * "My fooking factory runs 24x7 - what are you going to do about it?" .... "Yes but you didn't go for the full cluster version sign I'll see what I can do" ... You think I'm odd! No mate, my little company are well aware of automation and use it where we can but we are pragmatic and have to deal with a lot of reality. We could of course bind our customers to our iron will and enforce our policy and stuff. They would not work on weekends or other odd hours. They would not insist on doing things their way and they absolutely would pay us on time - they generally do 8)
- 0x0 9y agoIs the March 2018 update even out still? I thought they pulled it because it reconfigured all the NICs in the system, losing static IP configuration in the process...?
- rocqua 9y agoAny indication of whether this was actually exploited? I really don't want to do a full key-rotation routine. Also, does windows 7 map the entire address space into kernel memory? That is, would this have enabled direct memory access to other processors.
- MarkSweep 9y agoMy understanding of the article is that the page table itself was writable. So you an attacking process could map in the entire memory of the computer and read everything, regardless of what was in the kernel's version page table.
- caf 9y agoThe attacking process could also put whatever code it wanted into the kernel, and so give itself full access to everything on disk as well.
- 0x0 9y agoWow, that's crazy. About as bad as it gets for local privesc!
- ams6110 9y agoPredictable. Fixing old bugs introduces new bugs.
- kevindqc 9y ago99 little bugs in the code, 99 little bugs. Take one down, patch it around... 127 little bugs in the code.
- Arwill 9y agoI wonder for how long Windows as a software can continue to grow. I looked at the list of services, and its crazy. So much exotic functionality, and so many of what i don't ever need. Then the file system, there are even hidden folders managed by windows itself, that just grow and take up space. All that adds to complexity, and increases the probability for bugs. I wish there was a version of the OS that just shed all that unnecessary functionality and returned to basics. Something like a minimalist Linux distro, but able to run all games and office.
- ksk 9y agoHmm, but it appears that windows has fewer security bugs than Linux. Is there any data showing otherwise? (TBH, this is already unfair, comparing the kernel with an entire OS) https://www.cvedetails.com/top-50-products.php https://www.cvedetails.com/top-50-products.php https://www.cvedetails.com/product/47/Linux-Linux-Kernel.html?vendor_id=33 https://www.cvedetails.com/product/47/Linux-Linux-Kernel.htm... https://www.cvedetails.com/product/32238/Microsoft-Windows-10.html?vendor_id=26 https://www.cvedetails.com/product/32238/Microsoft-Windows-1... https://www.cvedetails.com/product/17153/Microsoft-Windows-7.html?vendor_id=26 https://www.cvedetails.com/product/17153/Microsoft-Windows-7... https://www.cvedetails.com/product/22318/Microsoft-Windows-8.html?vendor_id=26 https://www.cvedetails.com/product/22318/Microsoft-Windows-8...
- Erlich_Bachman 9y agoEven before that it's already unfair to compare a closed-source product to an open-source system. Bugs are much easier to find in an open-source system. It doesn't even by itself mean that there are more of them. If you look at the big picture, it's not like Windows is known for it's security.
- lmilcin 9y agoThis is what happens when devs are presented with a very complicated problem, extremely short deadline and enormous amount of pressure.
- gruez 9y ago>extremely short deadline they had 6 months.
- sddfd 9y agoAre you sure that that particular team inside Microsoft had full six months? Intel had 6 months.
- gerdesj 9y agoI'm pretty sure they had around six months give or take a day or so of oh shit in Intel. Of course, Intel may have actually simply broken the glass on a dusty old plan of action "In the event of ..."
- zer00eyz 9y agoDisaster plans are funny things. I have had the misfortune of having to pull them out twice in my career - in both cases they offered little in the way of guidance for the particular situation that came up. The set of unknown unknowns that are typically missed make most of them unless in all but the most narrow of cases, because many companies write them, and then forget them. Especialy if they are as large as intel.
- gerdesj 9y agoVery true, although I'm glad to say I have not had to break out one of my own yet for real. My first experience of a full on DR test was pretty humbling - NetWare servers backed up by the Unix troops via Legato. It turned out that the backups were good but restored at a pathetically slow speed (no reflection on the Unix systems but I suspect the Novell TSAs were a bit shag at the time). We updated "time to restore" estimations and moved on, after adding one or two other results of lessons learned. Do test your plans (this is not aimed at you personally zer00eyz - you probably know better than most). There are a lot of unknowns but the basic model of a real DR plan is pretty sound these days, if you can afford it or wing it in some way. An example: Another site, a suitable distance away. On that site there is enough infra to run the basics - wifi, a few ethernet ports, telephony etc. There should also be enough hypervisor and storage for that. Some backups are delivered there as well as on site. Hypervisor replicas are created from the backups (or directly) depending on RPO requirements and bandwidth available. The only thing that should be able to routinely access the backup files is the backup system (certainly not "Domain Admins" or other such nonsense". Ensure that what is written is verified. Now test it 8) .... regularly
- draw_down 9y agoMan, all our stuff is so shitty. Everything is just broken. Ugh.
- yuhong 9y agoThe fun thing is that even MS admitted it break non-PAE kernels and pre-SSE2 processors (in the most recent one). I have been fighting a similar bug in one of the Jet 4.0 patches for a while now.
- waldbeere 9y agoits normal for this company as win7 is end of life M$ will be breaking OS even more to force user to upgrade to windows 10 spyware edition. Where services are like service_23232 and when you disabled say hello to blue screen of death
- tambourine_man 9y agoSecurity is hard. I don't think I'd have the stomach to work on kernel or encryption code. The worst I can do here in userland is crash or delete data. And that's pretty bad already
- make3 9y agoyou likely write a lot more code than security/kernel-hardening professionals though. they just likely spend more of their time reviewing and researching than coding
- amluto 9y agoI think there is a spectrum of styles of people who work on this stuff. At one end, you just write some code and see if it works. At the other end, you read specs very carefully, think about what you need to do, and do it. No matter which approach you take, you still get blindsided every now and then.
- bzbarsky 9y agoYep. The most fun is when the spec has built-in security bugs. Especially when it only manifests in the interaction with a different spec.
- HankB99 9y agoI dunno. I think a program that produces subtly wrong results is the worst. It reminds me of a project I once did. It involved producing reports from tens of thousands of records including summing some of the fields. I was constrained to work on Windows so I put the date into an SQL server database and used MS Access to produce very nice looking reports. I reviewed the reports and everything "looked OK" so I handed them to the users for approval. They users were accountants. They added up the partial sums and pointed out that the results were only approximately correct. It turns out that MS Access is not so good at arithmetic. I restructured the reports to perform the arithmetic in the SQL queries and just use MS Access to format it for a pretty page. I also checked the arithmetic before handing the next revision over. Better testing (as in more than a superficial glance) would have caught this before review but there always exists the possibility that subtle bugs can sneak past even well thought tests. Just my own experience and opinion.
- stefan_ 9y agoI guess we know now that from the 3000000 files or what it was they boasted about, not a lot of them are some sort of unit test..
- egeozcan 9y agoHow can you test against an unknown bug?
- maltalex 9y ago> How can you test against an unknown bug? The point of testing is to make the unknown bugs, known.
- naasking 9y agoThe point of testing is actually to ensure certain classes of known bugs aren't present. You can't test for bugs of which you have no knowledge.
- stefan_ 9y agoThis one apparently meant that something intentionally mapped for kernel access only was now accessible from userland. That is exactly the tedious, boring issue someone manually testing a bunch of applications will never find, but unit tests are designed to.
- gerdesj 9y agoI'm just about to add this to our Risk Register. I'm thinking of 0.01 x 100 (our scoring system is 1-3 x 1-3.) That means I think it is very unlikely but seriously (I will probably offend someone if I let loose here) nasty.
- vardump 9y agoSo you'd give this 1 on a scale from 1 to 3? Presumably 3 being the most serious. That doesn't make any sense. If this bug is present, this is instant total control of a PC. That's as bad as it gets.
- stordoff 9y agoUnless OP edited his post, he appears to be scoring it 100 (i.e. it's off the scale).
- vardump 9y agoI misread grandparent post. The scale is 1-3 x 1-3, in other words, from 1 to 9. 0.01 * 100 is 1.
- gerdesj 9y agoI was being silly and making quite a few assumptions about readers - which is also daft. This is a really awful snag but it has all ready been patched if you apply them.
- stordoff 9y agoAh, I see. I was reading it as two axes, not a product.
- gerdesj 9y agoYes a product although the term "two axes" works as well. It's a pretty common way of quantifying "risk" into something that you can tabulate and form a todo list. You list your risks and give each one a score from 0-9 that is made up of "chance of happening" x "business impact or importance or whatever". You could score either as zero as well which will obviously cause the total score to be zero. I'll be changing our Risk Reg soon to become a Risks and Opportunities Register after a discussion in our last ISO 9001 audit. Not sure how the scoring scheme will work for that yet. This may look like a bit of a silly pseudo formal exercise but it really does help with decision making. There's nothing wrong with bending the scores either, if you are open about it. It is simply a way of prioritising a list of things to do in the end. I have to be a PHB sometimes as well as a sysadmin 8)
- amluto 9y agoYeesh. I didn’t know that Windows still uses the self-referential page table trick. This makes me very nervous, especially since they seem to keep it mapped in the user page tables. This seems likely to poke a big hole in ASLR if nothing else. It’s a huge target for write-what-where exploits.
- staticassertion 9y ago> This seems likely to poke a big hole in ASLR if nothing else. It’s a huge target for write-what-where exploits. How? Is it mapped to a static location?
- monocasa 9y agoIt is in Windows 7.
- staticassertion 9y agoGood to know, thanks.
- deleted 9y ago[deleted]
- nikital 9y agoAccording to the article, the self-mapping PTE is randomized in the latest Windows 10.
- ryuuchin 9y agoThey changed it in Windows 10 (RS1 IIRC)[1]. [1] http://www.alex-ionescu.com/?p=323 http://www.alex-ionescu.com/?p=323
- caf 9y agoThe tl;dr is that they're still using the self-referential page table trick, however the PTE_BASE is now randomised at runtime with dynamic fixups.
- blinkingled 9y agoI guess upgrade to Windows 10 is the message Microsoft is trying to get out here? Laying off all those QA and testing people will have some downside - MS seems to be letting older versions take the hit.
- contravariant 9y agoThat or switch to unix. Bad coding on one product isn't exactly the most convincing strategy to get people to try a different product.
- Silhouette 9y agoPerhaps. However, Microsoft has published very clear guidance on how long previous versions of Windows would receive support for, specifically including the period for security updates. Doing what you're describing is effectively reneging on that deal, and that sends a very different kind of message.
- blinkingled 9y agoSure, I have a hard time believing MS would purposefully screw their Win 7/8 enterprise customers - but the issue at hand suggests it's at the very least a byproduct of their new strategy of focus on Win 10 and the decision to do with less QA/Testers by involving more end users to participate in testing. Thus Win 7 users end up with slower, less tested patches and no hardware support backports. To be fair only the less tested patches sound terrible.
- flukus 9y agoWhat sort of QA would be doing memory access tests? Most I've worked with can't even do automation scripts.
- acdha 9y agoThat’s like saying most developers are WordPress install monkeys. It may be locally true but it’s not globally so. Good QA people – and I’m sure Microsoft and similar major players have plenty of them – are just as skilled as the developers but working at different goals. In addition to security, they’ll be working on scalability, detailed correctness tests, fuzz testing and other automation techniques, etc. If they can be replaced with a script, your employer has a management failure and is wasting a lot of money on short-term savings.
- pishpash 9y agoSo why does this only affect Windows 7?
- cptskippy 9y agoProbably because after Windows 7 they started a kernel rewrite , known as MinWin, to extricate the Win32 Userland tendrils that had crept into the Kernel since the NT days. https://en.wikipedia.org/wiki/MinWin https://en.wikipedia.org/wiki/MinWin
- container 9y agoThe article doesn't seem to indicate that MinWin started after Windows 7. If there has been a fundamental kernel change effort after Win7 (I'm not aware of one), maybe it has a different name?
- cptskippy 9y agoYou're right, for some reason my brain said Vista came after Windows 7. Given that 7 came after Vista my theory makes no sense.
- muricula 9y agoParts of the memory management code were rewritten for windows 10 to do fun things like randomize the location of the page tables. This fairly significant change wasn't backported to Windows 7. Then when they went to backport the meltdown fix to windows 10 they set a 'this page is user accessible' bit in the page tables by accident.
- deleted 9y ago[deleted]
- caf 9y agoA really simple test you can compile with cygwin - if it doesn't crash, the bug is present: #include <stdio.h> int main() { volatile unsigned long *ptr = (volatile unsigned long *)0xFFFFF6FB7DBED000; printf("%lx\n", *ptr); return 0; }
- testplzignore 9y agoI tested this on a Win7 x64 system with the 2018-01 (KB4056897) and 2018-02 (KB4074587) patches. It segfaulted. Hmmm.
- testplzignore 9y agoAhh, I was using a 32-bit gcc. 64-bit gcc shows it :) $ x86_64-w64-mingw32-gcc meltdown.c -o meltdown.exe $ ./meltdown.exe 1371183207
- BrianG61UK 9y agoBut can you find a March patch that makes the correct 64 bit version segfault? I can't :-(
- keir-rex 9y agoGrammar police warning: The comma in “if it doesn’t crash, the bug is present” actually makes the intention more difficult to understand.
- johnday 9y agoHow?
- kazinator 9y agoThe comma placement "if clause1, clause2" is extremely common. In the above sentence, there is no other place it can go, other than nowhere at all. "if, it doesn't crash ..." nope "if it, doesn't ..." nope "if it doesn't, crash ... " nope "if it doesn't crash, the " yep! "if it doesn't crash the, bug ..." nope "if it doesn't crash the bug, is ..." nope "if it doesn't crash the bug is, present" nope. When it is present, it does help to separate the if and then, particularly in the absence of the word "then". Without the comma, the prefix "if it doesn't crash the bug" can be scanned as a viable clause, only to find that the suffix becomes a fragment.
- lifeisstillgood 9y agoMy take on this is a little bit dumb, but, once upon a time, many moons ago, I thought I understood the CPU I acted upon, I could peek and poke and look up what was where. I mostly wanted faster, but what i got was more complex. Is there a way to just get faster without the complexity. What would a new cpu architecture and OS look like if we started again? is there room for open hardware to save us all?
- rwallace 9y agohttps://riscv.org/ https://riscv.org/
- userbinator 9y agoTempleOS.
- exikyut 9y agoSuperscalar processing was unfortunately a major step forward in terms of performance. The answer in https://stackoverflow.com/questions/8389648/how-do-i-achieve-the-theoretical-maximum-of-4-flops-per-cycle/8402970 https://stackoverflow.com/questions/8389648/how-do-i-achieve... is interesting; I'm particularly fascinated by the temperature warning (the answer author's CPU got to 76C in testing). My CPU's sitting at 30C right now. It maybe climbs to 48C if Chrome's being stupid, and 50+C if I'm doing something mildly taxing. I've never made it go beyond 60C IIRC. So, modern CPUs are so efficient that they're simply just never hitting their maximum throughput. I think that's pretty incredible. The sad thing about CPUs that don't use modern (superscalar, multi-stage, microarched, etc) design is that they just can't keep up. And people's OCD about speed and (more frequently) parallelization nowadays drives what they'll buy. Something had better have a killer feature if it isn't fast or highly parallel. So it's possible, but a huge headache. Whatever you built would likely be highly purpose-specific.
- notriddle 9y agohttps://millcomputing.com/ https://millcomputing.com/ ?
- well_done 9y agoWell, let's take a breath and be grateful that even MS can mess something like this up. One dev or 1000, who cares, whatever they chose did not work particularly well. Are "they" to blame? Yes. Are the engineers to blame? Probably not. Is management the culprit? We don't know. What's left? Next time your customers bug you about some random downtime caused by an overworked datacenter intern, don't feel stressed. Take the time to remember that even if you would've had billions of dollars, years of experience and thousands of employees, you could've messed up, just like MS did :)
- gerdesj 9y ago"Take the time to remember that even if you would've [sic] had billions of dollars, years of experience and thousands of employees, you could've messed up, just like MS did :)" When you are the direct, contracted, IT support for a company then you do have responsibilities. You might be considered responsible for timely delivery of patches - a fair argument in court I think. Mitigations might involve helpdesk logs as well as contracts. well_done: Your tone comes across as BOFH. I'm possibly a simple PHB who owns an electric cattle prod that is wired up to the mains (three phase) but I prefer to get sign off for a project via work committed and not threat done.
- freehunter 9y ago>Your tone comes across as BOFH I didn't read it like that, and I'm usually the first to read things negatively. I read it as motivational: don't feel bad about your own mistakes, even the big guys with tons of money and a lot of really smart people mess up sometimes. So cut yourself some slack and just do the best you can.
- gerdesj 9y ago"Next time your customers bug you about some random downtime caused by an overworked datacenter intern, don't feel stressed. Take the time to remember that even if you would've had billions of dollars, years of experience and thousands of employees, you could've messed up, just like MS did :)" I missed the :) which might sound a bit naff now but was probably intended to deflect comments like mine. Hit taken. However I did invoke BOFH which is (I hope) normally seen as an indication that a comment is not to be taken too seriously. EDIT: BOFH => Negative - nope, not here.
- kerng 9y agoSounds like Microsoft found and patched it independently already. Afterwards someone else (blog author) found it too, maybe by reversing the patch from patch Tuesday.
- computator 9y agoHas anyone actually confirmed this bug? The author seems to be an expert in low-level DMA security, but it would be nice to see independent confirmation. Reading through the comments so far, it doesn't seem so. The closest anyone comes is this: https://news.ycombinator.com/item?id=16693599 https://news.ycombinator.com/item?id=16693599 I was hoping to see someone who said: (1) I tested a Windows 7 X64 machine without the Meltdown patch (pre-December 2017) and couldn't read arbitrary memory. (2) Next I tested with Microsoft's Meltdown patch KBnnnnnnn (Jan or Feb 2018) and could read arbitrary memory. The system is insecure. (3) I then tested with Microsoft patch KBnnnnnnn (March 2018) and can no longer read arbitrary memory. They fixed it.
- caf 9y agoI did use a modified version of my short test program to actually test modifying the page tables to read a chosen physical address, which worked just fine. The bug is real.
- BrianG61UK 9y agoAnd KBnnnnnn that fixes it is which KB?
- deleted 9y ago[deleted]
- BrianG61UK 9y agoI finally found the fix. It's KB4100480. It makes the little test crash as it should. Phew!
- daveheq 9y agoThis sounds contradictory: "Only Windows 7 x64 systems patched with the 2018-01 or 2018-02 patches are vulnerable. If your system isn't patched since December 2017 or if it's patched with the 2018-03 patches or later it will be secure." "I discovered this vulnerability just after it had been patched in the 2018-03 Patch Tuesday. I have not been able to correlate the vulnerability to known CVEs or other known issues."