Microsoft finds privilege escalation vulnerability in Huawei driver
microsoft.com
microsoft.com
Am I close, if so: is there evidence that Huawei were using that access maliciously or was it just "to make sure their 'management software' retained it's place in the OS"??
We're talking about computers manufactured by Huawei here? Surely they can run code at a far lower level, is this MS and Huawei fighting over which of them "owns" the users computer?
[Slight aside: The MS page reads a lot like an advert. Nice link through to a page that itself has "start trial or buy" up top above the hero shot. Name drops some big vulns, Wannacry, DoublePulsar. Devalues the piece IMO because it seems the reason for them doing the work is solely to create an advert.]
Sure I get the warm fuzzies when a company like Google circa 2005 does something to help people with nothing obvious to gain from it. But in my experience companies like Google circa 2005 tend to become companies like Google circa 2019. People acting in their own interest are reliable.
Instead of the facile happytalk "Don't Be Evil", a much better slogan might be "Be as evil as you want, just don't hide anything from me and let's have an open and honest relationship"
Companies keep using the average user's technology ignorance against them. That was kinda cool and probably acceptable when you were the smart kid making a few dollars here or there, everybody loves the story of some genius hacker able to figure out the stock market and made a small fortune on a stunt they could never repeat, but this has gotten completely out of hand. It's gotta stop. We need to start acting in the user's best interests as if they knew as much about the business as we do. That's the only ethical way forward from here.
To cut short to my conclusion: We should be more humble about our less tech educated users and act accordingly.
Companies keep using the average user's technology ignorance against them.
So, then, do OSS things like vsCode, which are made for developers, go in the "Company plays to the users technological strengths" column"?People are smarter than metrics. Increase the incentives and you also increase the incentive to cheat. Sometimes the best you can do is insulate people from incentives, so people have the leeway to do the right thing without acting against their own best interest.
That said, regulatory incentives and punishments have their place too, IMO generally where the market isn't responding well, or information isn't available enough to allow for an efficient market, or as a response to some other regulatory market effects. But, as you noted, you'll often get some interesting behavior right at the edge of where the regulation kicks in because there's often a hard change instead of a gradual shift as an efficient market would allow.
I mean, consider Wall Street, Las Vegas, used car sales - the list goes on and on. It's a rich area of storytelling that goes back to the dawn of recorded history.
There is gaming of markets, but I think generally if it's not based on some regulation, it's because of information asymmetry (which is a market inefficiency).
All I was trying to point out in the prior comment is that there are different kinds of incentives. There are incentives that are constructed, and there are incentives that are natural. Constructed incentives are much easier to game. Natural incentives are emergent. Microsoft is incentivized to have good security for their OS now by the market in general, because it hurts them to not have good security (compared the the bast, where they could get away with lax security until it became a problem). That's emergent from the market and people deciding to use or not use their product. I wouldn't consider that "gaming the system", and if they did game it by talking a lot about security but not actually doing much, eventually the market should note that and respond appropriately.
Alternatively, Microsoft can reduce their tax burden by shifting business entities to different countries and shuffling how it appears their profit is created, so it's registered in a country with very little taxes, leading them to pay fewer taxes (not that they do, I don't know. I believe Apple and Google are reputed to do this). That's based on rules set by people, such as country boundaries and tax rates. Doing this could be considered "gaming the tax system". It requires specific changes to the rules to fix, it won't just shift naturally.
To me it appeared the comment you were responding to originally was using "incentive" in the pure form, meaning "benefit for doing so", and it appeared you were referring to incentive in the regulatory sense, where it's a human construction to influence behavior, but that's only a subset of the meaning.
My point is that real-world incentives are never perfectly aligned with such lofty, nebulous goals. They are about things you can measure such as how much money you can make. Making money is not the same as helping people and no incentive scheme is clever enough to make it so. Customers are often smarter than rules but even then, customers can be fooled. So there will always a way to make money without helping people and when you increase incentives, it also increases incentive to do things that aren't actually the goal.
This means that to some extent we rely on people to follow the spirit of the incentives and not to simply be amoral incentive-maximizers.
(This is closely related to the principal-agent problem, except the principal here is society in general.)
That's not what markets do. Markets are a means of efficiently and accurately pricing things in a responsive way. Some markets don't even have customers. That price may or may not be money, depending on the market in question.
> My point is that real-world incentives are never perfectly aligned with such lofty, nebulous goals.
For markets, definitely not, since that's not really what they are for, and any created incentive will at best attempt to move a market towards that.
> Making money is not the same as helping people and no incentive scheme is clever enough to make it so. Customers are often smarter than rules but even then, customers can be fooled. So there will always a way to make money without helping people and when you increase incentives, it also increases incentive to do things that aren't actually the goal.
Nobody here has said it is. The original comment noted "People acting in their own interest are reliable." I interpreted that to mean "when there are forces urging a person or group to act a certain way for their own self interest, it's easier to rely on them to continue acting that way". If Microsoft benefits from doing something that benefits others, it's easier to rely on them to continue doing that. I'm still not sure what point you were trying to make from that, since I'm not following how your latest comment relates to that or to my call for clarification, since I thought maybe you were interpreting the statement somewhat differently than I was.
As long as Autodesk is providing this program, students are:
A) not pirating their software,
B) becoming used to their tools (being completely unfamiliar with CAD as an engineer is a bad start), and
C) starting in the Autodesk ecosystem.
As long as students keep using Autodesk's platform, Autodesk is:
A) strengthening its market share
B) able to continue development (because the now-working previously students are using their software)
C) Relevant in the college setting, where professors have a large say in what goes and what doesn't.
There are probably always going to be college students, there are probably always going to be engineering jobs, and engineers will always need to have a CAD package. As long as those two things exist, Autodesk (or any other company with a CAD package) can gain goodwill, ensure relevancy, and invest in their future by giving their software away for free now. This is "gaming" a market in a long-term symbiotic manner.
Full disclosure: I'm an engineering student, in high school, and really appreciate the free copies of Autodesk Inventor and Dassault Systemes' Solidworks that I've gotten.
It's still ironic that Huawei get's some free audit for their stuff now and it's sold as they are bad, while everything is terrible - I won't install Logitech software after this epic bug here: https://bugs.chromium.org/p/project-zero/issues/detail?id=16...
It's a familiar pattern. If a large company were a biological organism, one of it's main pain signals would be negative PR. Prod the beast in other ways and it doesn't respond.
MS must have written a huge exposé on that one, can't seem to find it on their Security site though.
The knowledge needed to do so is far less than what is needed to pull the hack that Huawei did.
So to quote another user:
> Problem: any well written exploit will be designed to look like a mistake.
and given the above, I'm inclined to believe that this was meant as a deniable exploit ("honest mistake").
What I wrote above is what I miss in the MS's analysis. There are cleaner and simpler ways to achieve what Huawei tried to accomplish. I would be astonished that the person(s) having knowledge to write a kernel driver don't know about DACLs and how to use them to prevent tampering with a process.
EDIT: The article does end with guidelines. However, I'd be more happy if MS explicitly wrote "They should have done THIS (using exising, well-documented, UM only OS functionality) instead to achieve their goal."
Considering the physical memory mapping stuff, I wouldn't be surprised if the service doesn't have some roles firmware should have had - for example ensuring the battery charger is stopped when the battery is fully charged to prevent a fire.
Then you use a DACL than gives only PROCESS_TERMINATE permission [1] to the desired group (Administrators, Users, …). If killed, service control manager will figure out that the program exited abnormally and restart it.
[1] Overview of all permissions on process objects that can be allowed or denied in a DACL https://docs.microsoft.com/en-us/windows/desktop/ProcThread/...
Etrnal Blue was leaked from NSA and developed into WannaCry
While I agree with other posters that the wording of this disclosure is unnecessarily mixed with a PR piece, naming companies for me is crucial as it allows end users to assess their own impact o f a vulnerability and also puts a public track record on these vendors.
Like printer drivers they seem to be badly coded messes that create attack surfaces.
For a typical laptop everything except bios updates can be got straight from the vendor of the component.
I'm surprised microsoft haven't started distributing stuff like GPU, Chipset and other drivers themselves.
I guess, does it even matter at that point if you get ring-0 permissions? Probably shouldn't ever use their products regardless of the cause.
The Microsoft blog might stop short of calling it malware, but I think we don't need the faux politeness here. The fact that their malware also contained a privilege escalation (the "vulnerability") is merely icing on the cake.
Source: I've written kernel drivers and exploits.
Maybe we have different expectations of what a driver is. Take a look for yourself, even the updated PC Manager Software on their website still has the driver with the goofy shellcode in its installer (no idea if it's just not loaded now):
> malicious - adj. - having or showing a desire to cause harm to someone
I'ts goofy, and wouldn't pass a design review that I was a part of, but it isn't "showing a desire to cause harm". It just looks like a rushed design.
> about a driver whose pure function (this thing literally has no other value or purpose)
I see nothing about how this driver doesn't have any other functions.
> is maintaining an invincible NT_AUTHORITY process of their pre-installed management software
Because you want the hardware management process to be resurrected if it fails. They're not gaining anything from an attack perspective by deferring to user mode, the process isn't hidden, and they're already running as a kernel driver so they have full control of the system as it is. In Raymond Chen's parlance, they're already on the other side of the airtight hatch.
> Maybe we have different expectations of what a driver is.
I mean, Minix ascribes it's uptime and reliability to a resurrection server. Is this a much crappier design? Yes. Is it such a bad design that it's malicious? No, that's absurd.
> Maybe we have different expectations of what a driver is.
I expect drivers to defer everything they can to user mode so they don't crash the kernel. That's one of the reasons why APCs exist in the first place.
> Take a look for yourself, even the updated PC Manager Software on their website still has the driver with the goofy shellcode in its installer (no idea if it's just not loaded now):
Oh no, they didn't take that out of their package, but even Microsoft says that they fixed the vulnerability, and quicker than responsible disclosure asks for.
Obviously, you didn't look at it.
This is the irony of it all. There is nothing simple about writing a device driver to do what literally three lines of code in userland registering a service could have achieved. It is the furthest thing from a rushed design you could possibly do; it is taking the wrong turn 10 times and incurring exponential costs each time. That is why it's called a backdoor or malicious; it demonstrates unique niche knowledge in things that are the furthest imaginable distance from the shitty .NET amalgamation that their actual PC manager software is.
Particularly given that they describe how there's multiple ioctls.
And I can tell you from experience that relying on the service manager for a full watchdog solution is fraught with peril. It'll catch hard crashes, but not for instance dead locks.
As the full saying goes.
Never attribute to malice what can be explained by stupidity...but don’t rule out malice.
All code is security code.
Debian disagrees. They are wrong to do so.
This doesn't mean the actual flaw was malicious, but being actively exploited, it seems intent doesn't really matter.
> While monitoring alerts related to kernel-mode attacks, one alert drew our attention:
>The alert process tree showed an abnormal memory allocation and execution in the context of services.exe by a kernel code. Investigating further, we found that an identical alert was fired on another machine around the same time.
This shows code injection taking place, via the exploited code. You are right that they don't mention what code was injected (probably they don't know)
Their scanner doesn't show any exploitation happening, and they don't say that it does.
You are right that they don't seem to know what code was being executed. Just that some code (be it real code or random garbage) was injected and executed.
They know the code it's running for the most part, it's the CreatProcessW stuff they talk about.
Inspecting MateBookService.exe!main revealed a “startup mode” that revived the service if it’s stopped – some sort of watchdog mechanism meant to keep the Huawei PC Manager main service running.
I agree that it’s hard to prove malice, but why should any PC management software go out of their way to ensure that it never gets shut down?
Like this stuff is usually designed by EEs and they love their watchdogs at all levels. Having a watchdog is very standard for this stuff.
I’m no expert on device drivers but to my knowledge, Windows already allows you to manage devices and install drivers through Device Managers.
Then if drivers are already installed for the various devices and hardware components, what exactly is the hardware management service managing on top of the individual drivers?
I am asking this as the only plausible reason to be doing this (at least for me) is if Windows isn’t providing enough tools for device management that needs coordination between the hardware components on the machine, so I would appreciate someone with more knowledge to shed some light on the subject.
> why should any PC management software go out of their way to ensure that it never gets shut down?
The Windows 10 kernel itself goes out of its way to make sure the Windows update service isn't permanently shut down.
Plausible deniability. If you were to implement a backdoor for a company, would you write "professionally done" all over it?
Given the circumstances, one might wish to err on the side of caution.
That's what you need to achieve plausible deniability. You'll need to make it look innocent.
(I also write Windows kernel mode drivers.)
Either Huawei's driver developers are both incompetent and stupid or they're injecting malicious backdoors.
Please, continue.
But FWIW, it's a pretty common thing for shitty drivers. Here's one example: https://forum.xda-developers.com/showthread.php?t=2057818
This is simply news because it's Huawei and many want them to be guilty of backdooring US entities. Perhaps they are, but no more many other "respected" US companies.
Edit: I'm not sure if it's considered appropriate to ask for credentials on HN. There's one way to find out :)
The only reasonable usage of such a situation is for the magician him/herself, to study his/her own performance. And even then, it is not usually done that way.
And while there's better ways to handle it, and it wouldn't pass a design review of mine, it's pretty common to make a driver specific /dev/mem equivalent. For isntance https://forum.xda-developers.com/showthread.php?t=2057818
Any driver for a multiuser OS that essentially bypasses protection mechanisms by the kernel for non-root users is broken, period.
There is no argument about it.
My guess is someone had a hard time deciphering MSDN rather than some malicious motivation. I've had to wade through the CreateProcess and svchost docs before, the options and security restrictions are labyrinthine. I'm not sure how some Chinese engineer reading a translation could much better.
It's understandable though, given their affiliation with the persecuted Falun Gong.
(Looks like the original URL has been changed to an actual Microsoft authored page.)
It's the anti-"current Chinese policy" and the way it treat dissidents, minorities, journalists etc.
Epoch times is run by Falun Gong.
The Chinese official government line is that Falun Gong is an extremely dangerous cult that should be repressed. I've seen people on the English language internet intentionally comparing it to Jim Jones, David Koresh, etc.
In reality it seems to be more like a Chinese version of Scientology.
As far as I know, among them, Falun Gong and The Church of Almighty God was making false promise about their ability of "getting people back on their feet".
I don't know why people here are suddenly on fire when saw me put Falun Gong and cult together. In China, we use word "神棍"[0] to describe someone who fake their supernatural ability and pretend to be the messenger of god. And the word was come out before CCP even a thing, that alone can tell you something does it?
[0] https://zh.wikipedia.org/wiki/%E6%A3%8D%E9%A8%99#%E7%A5%9E%E...
>Our discovery of the driver vulnerabilities also highlights the strength of Microsoft Defender ATP’s sensors. These sensors expose anomalous behavior and give SecOps personnel the intelligence and tools to investigate threats, as we did.
>Anomalous behaviors typically point to attack techniques perpetrated by adversaries with only malicious intent. In this case, they pointed to a flawed design that can be abused. Nevertheless, Microsoft Defender ATP exposed a security flaw and protected customers before it can even be used in actual attacks.
Seems to me a lot like "the ATP sensors and the SecOps did what they are supposed to do" followed by some self-patting/self-applauding on how good the MS technology and guys are good at it.
But can each country has their own manufactured computer and os? Or region?
The world is turned upside down.