4 ms·
They kind of have to, though. If malware exploits a privilege escalation vuln, what's the AV going to do about it when it's reduced to the software equivalent
by labelbabyjunior 6mo ago
They kind of have to, though.
If malware exploits a privilege escalation vuln, what's the AV going to do about it when it's reduced to the software equivalent of a UK police officer? Observe and report? Stop or I'll say "stop" again?
AV requires great power, which requires great responsibility. The second part is what often eludes AV developers.
- EvanAnderson 6mo agoThe OS should do the SYSTEM-level lifting and scanning processes and behavior analysis should run sandboxed as low priv processes. It would require a clearly defined API and I feel like MSFT was always reticent to commit, leaving AV manufacturers to create hacky nightmares.
- labelbabyjunior 6mo agoWell the OS should do nothing—remember MS was taken to court over that—but better privsep on the part of the AV, sure. Technically, Defender can be replaced with 3rd party AV.
- bux93 6mo agoWindows has separate SeBackupPrivilege for backup software, so why not for AV?
- arcfour 6mo agoWhat would this privilege look like that is meaningfully different from SYSTEM while being properly protected from/able to deal with malware that has an LPE?
- formerly_proven 6mo ago“Because the remediation component requires SYSTEM, the entire AV needs to run as SYSTEM and we have to unpack malware in the kernel”