4 ms·
What is the vulnerability here? An admin user can do admin stuff. Shocking.
by fisf 4y ago
What is the vulnerability here? An admin user can do admin stuff. Shocking.
- ImPostingOnHN 4y agoif you believe you know the answer to the question, why ask it?
- Thorrez 4y agoYeah, I'm not 100% sure. I'm not sure what the threat model for Uninstall Protection is. The official description page isn't completely clear. >Uninstall protection prevents unauthorized users from uninstalling the Falcon Agent >The “Maintenance Manager” role is available which grants permission to access the maintenance tokens. This role must be enabled against the Falcon user’s account in order to obtain maintenance tokens or manage policy related to Uninstall Protection. Putting those 2 sentences together seems to lead to the conclusion that if someone doesn't have the "Maintenance Manager" role, that person will be prevented from uninstalling the Falcon Agent. It's unclear to me if all admin users are considered to have the Maintenance Manager role. https://www.crowdstrike.com/blog/tech-center/uninstall-protection-for-the-falcon-agent/ https://www.crowdstrike.com/blog/tech-center/uninstall-prote...
- Sohcahtoa82 4y agoOn Windows, there are things that even the Administrator user can't do, at least not directly. One example I know off the top of my head because I know from experience is accessing Bluetooth encryption keys in the registry. Even if you launched Regedit as Administrator, you'll get ACCESS DENIED reading them. But if you use `psexec` to start Regedit as the SYSTEM user, you'll have access. My guess is that CrowdStrike installs itself with permissions that prevent Administrator from uninstalling it.