12 ms·
Microsoft finds privilege escalation vulnerability in Huawei driver
- lostmsu 8y agoOriginal source, much better info + technical details: https://www.microsoft.com/security/blog/2019/03/25/from-alert-to-driver-vulnerability-microsoft-defender-atp-investigation-unearths-privilege-escalation-flaw/ https://www.microsoft.com/security/blog/2019/03/25/from-aler...
- dang 8y agoOk, we've changed the URL to that from https://www.theepochtimes.com/microsoft-finds-backdoor-in-huawei-laptops-that-could-give-hackers-access_2863926.html https://www.theepochtimes.com/microsoft-finds-backdoor-in-hu....
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- saagarjha 8y agoBetter article: https://www.microsoft.com/security/blog/2019/03/25/from-alert-to-driver-vulnerability-microsoft-defender-atp-investigation-unearths-privilege-escalation-flaw/ https://www.microsoft.com/security/blog/2019/03/25/from-aler...
- dang 8y agoChanged now. Thanks!
- msie 8y agoBackdoor is such a loaded word to use for a vulnerability. Especially since Huawei is involved. Shame on the person who came up with the title and the reporter who uses the term in the article.
- z2 8y agoIt's a loaded newspaper: https://en.wikipedia.org/wiki/The_Epoch_Times https://en.wikipedia.org/wiki/The_Epoch_Times
- murderfs 8y agoThe Epoch Times is a Falun Gong propaganda arm, and Falun Gong is basically Chinese Scientology that the CCP has been trying to stamp out.
- verall 8y agoWhat? Maybe the Epoch Times is biased, but the Falun Gong is nothing like scientology: it has no fees and isn't trying to coerce anyone to join. It's a minority group that is persecuted by the CCP.
- yourbandsucks 8y agoWhat kind of minority group? They're religious kooks. That doesn't mean they deserve to be stamped out, necessarily, but they're also not a "minority group" by the common definition of the term.
- will4274 8y ago> they're also not a "minority group" by the common definition of the term. How not? The Chinese government locks them up, murders them, and harvests their organs because they disagree with the communist party. Sounds like pretty classic "authoritarian government vs minority group" to me.
- 8y ago
- deleted 8y ago[deleted]
- pbhjpbhj 8y agoFrom scanning the page it sounds like Huawei used a hack to make their MateBookService unkillable, unremovable, by unhooking in to services.exe. That in the process of that they left the possibility that the device they were using HwOs.*\.sys was only protected from being used by checking the program had the right path, thus leaving it open to crackers (it being basically g+rw) to use to get the ring-0 permissions needed to run the "stay resident"-type hack Huawei were using. And that in turn meant a process could overwrite MateBookService and gain it's own privelege escalation?? Am I close, if so: is there evidence that Huawei were using that access maliciously or was it just "to make sure their 'management software' retained it's place in the OS"?? We're talking about computers manufactured by Huawei here? Surely they can run code at a far lower level, is this MS and Huawei fighting over which of them "owns" the users computer? [Slight aside: The MS page reads a lot like an advert. Nice link through to a page that itself has "start trial or buy" up top above the hero shot. Name drops some big vulns, Wannacry, DoublePulsar. Devalues the piece IMO because it seems the reason for them doing the work is solely to create an advert.]
- nisa 8y agoI guess it's because Defender ATP is basically some kind of cloud-service for security and because everyone is running Windows for everything it's targeted at managers or so. I have no idea how useful it is, but I guess they have some advanced techniques to detect certain attacks (like this one, or the dropped DoublePulsar) - If you have to defend some important Active Directory Setup it's probably not a bad deal. It's still ironic that Huawei get's some free audit for their stuff now and it's sold as they are bad, while everything is terrible - I won't install Logitech software after this epic bug here: https://bugs.chromium.org/p/project-zero/issues/detail?id=1663 https://bugs.chromium.org/p/project-zero/issues/detail?id=16...
- pbhjpbhj 8y agoWow, that Logitech app is crazy huh, they just opened a port from all their Logitech Options users to anyone enabling them to make a remote keylogger. MS must have written a huge exposé on that one, can't seem to find it on their Security site though.
- Jonnax 8y agoIs there any value in these driver add-on tools that manufacturers ship? Like printer drivers they seem to be badly coded messes that create attack surfaces. For a typical laptop everything except bios updates can be got straight from the vendor of the component. I'm surprised microsoft haven't started distributing stuff like GPU, Chipset and other drivers themselves.
- allset_ 8y agoWith Win10 they do ship those drivers through Windows updates.
- kiwijamo 8y agoThey’ve done it for previous versions as well. I think that practice goes back to Vista at the very least.
- rincebrain 8y agoIt started in Vista, AFAIK, but it didn't really become reliably useful for _most_ of the drivers on even relatively common hardware configurations until 7, and even now it's still not complete (I installed a Coffee Lake-era Intel desktop with Win10, and I still got to play Hunt the Unknown Device Driver even after the endless reboots for updating had installed every driver Windows Update offered, and that's for onboard peripherals, not a fly-by-night USB device or PCIe card.)
- chronogram 8y agoFor future people with troubles you could go try sdi-tool.org which works nice for me and a lot of friends for years now.
- hojjat12000 8y agoI have a Matebook D. The manager is useful to update your drivers all at once (plus your bios too). It's the only program that comes with the laptop, so no bloatware. I've been happy with the laptop, and I don't think there is any malice here, just a stupid mistake, that they already have fixed it.
- ngcc_hk 8y agoIt is not what they can do now and be fixed but what tubes can do in the future. But can each country has their own manufactured computer and os? Or region?
- mrtweetyhack 8y agoThanks a lot Microsoft. Now they have to create a new backdoor.
- Uhrheber 8y agoMcrosoft! Finding a privilege Escalation! In someone else's software! The world is turned upside down.
- jorblumesea 8y agoGiven China's preponderance to mass surveillance and Huawei's obvious ties to the state, it's probably smart to take a critical look at anything they write. Willful ignorance and incompetence or cleverly crafted vuln with plausible deniability? I guess, does it even matter at that point if you get ring-0 permissions? Probably shouldn't ever use their products regardless of the cause.
- blarpleBlarbz 8y agoHonestly, Microsoft's shitbird security track record for the past umpteen years is such a clusterfuck that it's impossible to consider them as doing anything other than deliberately shipping the leakiest possible operating system to as many Americans as possible, with express intent to open a general surveillance portal exposing every user to analytical scrutiny for decades on end. And with that, also a shrug, because yoooooooouuuuu asked for it! From 95 to 98 to NT to 2000 to XP to Vista, and on and on, and it only gets worse. But hey, woah! Now someone else is sticking their nose in front of America's magic mirror??? My goodness! Heavans to Betsy! If Microsoft hadn't been such utter garbage since nineteen ninety fucking five, interrupting my fucking life with unstoppable automatic updates "for security patches" every other week... patches that forbade me from unplugging a machine in my own home, lest summarily it brick itself, I might be inclined to raise an eyebrow at yet another vulnerability, but alas... That's not the years of Microsoft history I remember.
- monocasa 8y agoThe thing already had ring 0 permissions, the code with the bug in it is a kernel driver.
- zvrba 8y agoWeird approach by Huawei. If you want a program to stay up and running, you write a windows service; autostart with restart for recovery in case of crash. The service process can set its own DAC so that only SYSTEM can open its handle, hence the process in inaccessible/unkillable to ordinary users, even administrators. The knowledge needed to do so is far less than what is needed to pull the hack that Huawei did. So to quote another user: > Problem: any well written exploit will be designed to look like a mistake. and given the above, I'm inclined to believe that this was meant as a deniable exploit ("honest mistake"). What I wrote above is what I miss in the MS's analysis. There are cleaner and simpler ways to achieve what Huawei tried to accomplish. I would be astonished that the person(s) having knowledge to write a kernel driver don't know about DACLs and how to use them to prevent tampering with a process. EDIT: The article does end with guidelines. However, I'd be more happy if MS explicitly wrote "They should have done THIS (using exising, well-documented, UM only OS functionality) instead to achieve their goal."
- londons_explore 8y agoPerhaps they wanted the service killable, but for it to always restart? Considering the physical memory mapping stuff, I wouldn't be surprised if the service doesn't have some roles firmware should have had - for example ensuring the battery charger is stopped when the battery is fully charged to prevent a fire.
- YawningAngel 8y agoThat isn't a safe approach, as your laptop becomes a file hazard as soon as you install any other OS (even clean windows!). I'm not sure that this is a more robust mechanism for achieving that outcome than a Windows service in any case.
- HeWhoLurksLate 7y agoPerhaps in hardware?
- zvrba 8y ago
- kobi7 8y agoso many spies... Why are they afraid of saying that China is trying to spy and steal your intellectual property. It's an established fact by now.
- mortb 8y agoMaybe, as some posters in this thread are suggesting, this should not be read as a PR article. This should be read as a "Huawei (and others) we are watching you. Stop doing those things we are able to spot your doings, and we are willing to show the world". Of course the article touts about the ability of defender and their forensics team, but there is definitely a possibility that another message is being conveyed. As I am working mostly in web etc I have no experience in writing drivers so this is quite a few software layers below my comfort zone. However, to me having read the article, it seems that the "Watchdog" goal achieved by Huawei's code is done in such a round about fashion that is either a combination of "skilled but sloppy programmer" or "skilled and not sloppy but wanting to be perceived as sloppy". Some context, WannaCry and DOUBLEPULSAR are mentioned several times. Read about the NSA backdoors: https://en.wikipedia.org/wiki/EternalBlue https://en.wikipedia.org/wiki/EternalBlue https://en.wikipedia.org/wiki/DoublePulsar https://en.wikipedia.org/wiki/DoublePulsar Etrnal Blue was leaked from NSA and developed into WannaCry
- mortb 8y agoAnother piece of context, the article says that the issue was resolved together with Huawei. Why then make a publicly available article about it naming the company? Why not just patch and pretend that there were no issue, or patch and with a more generic description "we have implemented a mechanism to monitor drivers that might try to execute arbitrary code"?
- tastroder 8y agoThat happens all the time as it's relatively normal to do so in this type of disclosure . With the political focus on Huawei these days it's likely just people noticing this message more than others, it's not like other big manufacturers show better security practices. With Huawei in particular, MS as a US company really couldn't have omitted the name from the disclosure without being put in a weird spot later down the road. While I agree with other posters that the wording of this disclosure is unnecessarily mixed with a PR piece, naming companies for me is crucial as it allows end users to assess their own impact o f a vulnerability and also puts a public track record on these vendors.
- 8y ago
- jaclaz 8y agoI may be cynical but: >Our discovery of the driver vulnerabilities also highlights the strength of Microsoft Defender ATP’s sensors. These sensors expose anomalous behavior and give SecOps personnel the intelligence and tools to investigate threats, as we did. >Anomalous behaviors typically point to attack techniques perpetrated by adversaries with only malicious intent. In this case, they pointed to a flawed design that can be abused. Nevertheless, Microsoft Defender ATP exposed a security flaw and protected customers before it can even be used in actual attacks. Seems to me a lot like "the ATP sensors and the SecOps did what they are supposed to do" followed by some self-patting/self-applauding on how good the MS technology and guys are good at it.
- brianpgordon 8y agoSo these "alerts" are coming from Microsoft's cloud-powered anti-malware service? It's kind of disturbing that they have enough data on Microsoft servers to conduct such an in-depth after-the-fact investigation of events on an endpoint machine. Are businesses really OK with sharing telemetry on this level?