Razer bug lets you become a Windows 10 admin by plugging in a mouse
bleepingcomputer.com
bleepingcomputer.com
Need local admin and have physical access?
- Plug a Razer mouse (or the dongle)
- Windows Update will download and execute RazerInstaller as SYSTEM
- Abuse elevated Explorer to open Powershell with Shift+Right clickThis has recently got me service access on an old (but new in 2009!) ultrasound machine, for example, for getting raw data and dicom images off in a hurry when the proper authentication details were lost...
The real boss move was navigating a machine with a UI that involved a trackball, keyboard, touch screen(s), touch pad, weird array of custom buttons and a truely stupid menu system.
Configuring US machines is horrible.
But my major US machine rant is them burning metadata into the images (rather than displaying DICOM tags as an overlay). It’s is beyond ridiculous.
US machines do a lot of fun physics on proprietary FPGAs. For inexplicable reasons, every one I've ever worked with or done echo with saves the images as some variation on a theme of screenshots, shoehorned badly into a dicom wrapper, with the metadata burned at 640x480 px (or similar) on top. Even for clever derived modes like doppler -- even for annotations showing things like cardiac E/E' or E/A. They are laptops with a custom pcmcia / pcie card and a 100k-UNIT_OF_CURRENCY price tag, inevitably running a shitty OS with a shittier custom UI...
The hell of US knows no bounds. Most modalities calibrate a display and then display images (with varying degrees of post processing). US calibrates the screen, sometimes with each boot or even each probe change. Their black levels are abysmal.
> saves the images as some variation on a theme of screenshots
GE has a habit of making DICOMs from screen grabs. I’ve seen it on their PET, CT and MR systems. It causes irritating problems - like reference lines won’t work so you can’t cross reference.
When I inevitably got caught I remember my dad let me have my own user, but put some sort of further time-restriction software on the PC, no idea what it was, but I figured out that if I timed Ctrl-Alt-Delete at just the right time during the start cycle, I could, if I worked fast enough, end the process before it locked me out of login. XD
Oh to be a 90s kid.
[1] to be fair though we didn't update Windows immediately on release and never had '98.
[2]https://www.myabandonware.com/game/thinkin-things-collection...
I figured out that putting a certain character in front of a file name made it not show up in explorer. So I did that to a folder in my home directory and put all my stuff there, accessing them from the command line instead. Never had them deleted, again.
Similarly, I've had Windows 10 spam me about a paid subscription for Dolby Atmos.
This is just one of several reasons that I don't use Windows anymore.
It works fine without it, but whoever programmed this thing has never heard of a "No, and Don't Ask Me Again" Button.
In regedit, F3 for razerinstaller and add a DWORD key "Start" with value "4" .
Yea that's how far they went XD
What's the easiest way to scan whole windows file system for directories with this issue?
tree c:\ /f prn
Source: https://docs.microsoft.com/en-us/windows-server/administrati...If you want to setup the LED lights for your fans - you must install this crap; if you want to customize your mouse somehow - install this other crap. Same companies have not one, but two software suits that manage different peripherals.
Razer is the worst of these. Asus ROG takes second place.
For RGB controls check out https://openrgb.org/.
The UI is pretty bad but once you figure it out it works great otherwise.
As an aside, are there any periferal brands that are known for minimalist drivers etc?
[0] https://www.reddit.com/r/Amd/comments/oyu1j6/thanks_powercol...
Seriously what are these manufacturers thinking? It's like they go out of their way to make things as bad as possible.
Given Razer's general shenanigans, such as tracking mouse and keyboard behavior and sending it to their cloud (without which, by the way, much of their new hardware simply won't work), their unintentional breaches of security pale in comparison to their deliberate breaches of privacy.
"What are you crying for, Windows 10 piece of shit settings app that doesn't understand how to let me control individual sound devices the way I want?"
My laptop came with this crapware too and it pissed me off so much I reverse engineered it into a simple free software program that turns all the stupid lights off instantly.
Turns out all these shitty apps do is send a bunch of USB configuration packets which were easy enough to figure out with wireshark. The Razer products do the same thing, open source code is already out there. Sometimes they use convoluted interfaces like I2C and ACPI/WMI. Haven't had luck with these.
For anyone else reading this who’s feeling smug because they would never buy such a device: you don’t need to; only the attacker needs to. Windows will happily download and install the drivers automatically the first time the device is plugged in.
In this case, why does a mouse driver need to live in the kernel in the first place? Microsoft should be improving the HID layer to make that unnecessary.
Foe a $2 example, see: https://github.com/chris408/digispark-usbkey-board (PID/VID set here: https://github.com/chris408/digispark-usbkey-board/blob/6f0a...). And yes, it can be much, much smaller than this.
You are sorely mistaken.
https://googleprojectzero.blogspot.com/2015/07/one-font-vuln...
There could be another option: If you want to ship it without exposing the source, you need your drivers vetted by some third party that has access to the code.
Just because I want to grant system access to a relatively simply USB driver doesn't mean I want to grant the same access to a 150MB UI app.
If I were attacking the system along this vector, my exploit would sit in the USB driver, not the UI code.
You could take advantage of being SYSTEM much earlier along this cycle and still take control of the computer. This is actually a very nasty bug in how arbitrary code can be run at SYSTEM level when inserting a usb device.
And once malicious code is in kernel space it wouldn't even need access to an attack surface.
Why is it so hard to priorities good drivers? Or is it just impossible to hire good driver developers?
Absolutely. The overwhelming majority of hardware companies are not competent enough to write drivers of any kind. They're not even competent enough to write user space software. They treat software as a cost center. To them software's just wasted money, to be made as cheaply as possible and only because they have to.
Linux kernel is great as a litmus test. If a company can't get a driver into the kernel it shouldn't be trusted with writing drivers of any kind.
the development of the application is driven by concerns with UX trendiness, brand management, marketing, telemetry, etc.
The major difference between user mode programs and kernel mode programs is security and stability (at least in this context). Things in kernel mode have basically no restrictions on what they can do, from a security sense. Things in kernel mode can also crash the thing they're part of: the kernel. That's a blue screen (or cyan, now). One of the reasons those blue screens are so much less common is that Microsoft really pushes OEMs to make userspace drivers. If they die, they just get restarted, no need to crash the whole OS.
The other issue is of installing user-facing utilities alongside the driver. That needs to stop. It's orthogonal to the kernel vs user mode issue though, because Razer can make their UI run in kernel mode. It's a horrible, terrible idea that no one will enjoy, but they can. And really, we want the drivers to run in user space too if we can.
Windows should not install random drivers from the Internet when a non-admin user is logged in.
My work was only confidential (and that only by default) but it was definitely interesting to be an in environment with secret sauce about, and processes for handling it. (Fire procedure not being drop everything and exit the building, for one.)
In a perfect world, or at least a tech user world, sure. But there was a compromise to make, either this (and that behavior can be disabled), or user stayed on admin account at all time. Which was the norm for windows since forever. Even on vista people disabled UAC.
From that point of view this is still the more secure outcome, at least the admin hatch is only broken through sometimes, instead of always.
Not saying this shouldn't be improved, but if you look not only at the end result but also at the path to get there, it does make some sense.
In the end, the driver is running executable code which could (I believe) just start an EXE install wizard anyway so this seems unpreventable.
If only Razer customers are affected then, sure let's put all of the blame on Razer but this affects everyone using Windows 10. There are some very good reasons why you cannot simply install device drivers without admin rights and if Microsoft chooses to wave those rights for trusted suppliers then they can very much be blamed for this kind of oversight.
Now, it's true that MS has a flawed architecture here. But it's not inherently so as I see it. Third party devices do need automatic driver install of some form. Drivers do need elevated privileges. Microsoft's model was that they'd audit and authenticate the software through the WHQL process. And it turns out that let a really glaring hole through.
But the problem is just really, really hard. If you want third party driver software to run on your system (and not all vendors want that: iOS has nothing of the sort, obviously, and Linux vendors ship all the drivers themselves) then you need to be prepared to do a ton work ensuring it's safe.
Not to let Razer off the hook here, because they're responsible as well, but in doing as you've described here, Microsoft are have willingly placed the onus for security on themselves.
>Linux vendors ship all the drivers themselves
Not all of them. Nvidia is a famous exception to this. If you want to install their drivers, I don't know of a Linux distro that will allow you to without root privilege.
Now, that user experience broadly sucks vs. plugging the same PCIe card into a Windows box and booting it up to get an automatically installed driver. But it's not subject to the same security problems either, which was my point.
Would you be ok with the AMD kernel driver launching a web browser as root on first boot? Or every boot?
Sure, but a tonne of them come with them by default these days
Clearly Razer played a role here since they were doing something that is (from my experience) unusual by presenting a wizard during a Windows Update installation. On the other hand, this is a fault that Microsoft has to fix.
I don't see why. Particularly not if the user wouldn't have permissions to do it themselves. If the user doesn't have permission to install a driver, there is probably a good reason for it and the system shouldn't be automatically installing drivers on their behalf either.
If you accept the paradigm of third party hardware sales at all, then you need to have some kind of automatic secure install.
If Razor can't make their gamer mouse autoinstall drivers, then neither can Logitech. This would be an equal playing field.
> (or flee to another platform entirely).
If somebody can't type in their own password when prompted to install a driver, it probably isn't their computer in the first place. The computer almost certainly belongs to their school or employer, or at least another family member, and I think any of those would rarely be receptive to "Please replace your dell with a macbook because the turbo button on my gamer mouse doesn't work."
Furthermore, the gamer mouse will have basic functionality without the razor driver anyway, and from my experience I doubt most clueless computer users would notice the difference. If they can "click the internet button and the google shows up", then the mouse is working as far as most users of this sort are concerned.
Only if your user doesn't have admin permissions you need to type in a password to run something elevated.
This is a mouse. It works perfectly fine as a USB HID device. The software install is to unlock optional features on the device, and that can be done after the user has authenticated to the host and gone through a security elevation prompt.
In fact there are precious few third party devices without a usable built-in driver that absolutely need to be available before the user had logged in. I can't think of any.
That's not true. It may help you to watch the video.
The user was authenticated as a regular logged-in user. It was the driver installation that had elevated rights as SYSTEM, and there was no security elevation prompt.
I assume the mouse driver only bypasses it because it wants to have the driver installed before the user has logged in.
Also it should be if possible minimally fit for use without extra software even if all features aren't available.
There is no way any of this should ever happen automatically. People installed custom hardware for windows in the year 2000 and it worked fine then.
It's a flaw in Windows culture, where application publishers and device manufacturers are allowed and perhaps even encouraged to run amok, especially at install time, and run all manner of bespoke procedures with elevated privileges.
And it's a flaw in device manufacturer culture, where first-party device ‘drivers’ are expected to be bundled (sometimes optionally, sometimes by mandate) with entire applications for managing them, usually with flashy wizards and always-on GUIs that live in the system tray. More and more, it seems like manufacturers push that shit so they can track users usage of their devices, as well.
This is as much a result of device manufacturers' marketing teams' ruinous desires for customized, unique user interfaces and branding as it is a result of anything else. This kind of shit is really alien on platforms where universal management interfaces are the norm, package installation is expected to be well-behaved and non-interactive, etc. It's par for the course on Windows (and significantly so, but to a lesser extent, on macOS).
OAuth for Windows, I rest my case.
My mouse driver is asking for a firewall exemption (2019) - https://news.ycombinator.com/item?id=28274305
Normally we'd downweight one or the other (https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor...) but in this case I don't think that makes sense.
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor...
https://hn.algolia.com/?dateRange=all&page=0&prefix=false&so...
In this case that didn't seem indicated though.
One is a twitter thread about a Roccat Mouse driver.
This one is about a security vulnerability in Razer software.
Even companies with the most automated non-existent customer service know they need to provide separate channels for legal and security so that actually get read by a human.
Their response after the issue hit social media was far more decent than companies have done in the past:
> I would like to update that I have been reached out by @Razer and ensured that their security team is working on a fix ASAP. Their manner of communication has been professional and I have even been offered a bounty even though publicly disclosing this issue.
Darned auto-carrot strikes again, and I was far too late noticing to be able to edit. Two in a short post, I'm not sure if the slide-keyboard is getting worse over time or my coordination is failing as I age but something seems to be failing more these days than it used to…
Maybe customer support agents are just very badly trained. Or there is a second/third/forth level that investigates those emails, but they are getting too many messages to go through all of them.
its not responsible to disclose in secret and hope the company doesn't ignore you or curb stomp you to oblivion
its not responsible to push for a little pat on the back and maybe an undervalued $ compensation
proverbially nuke them from orbit, responsible is not a factor here
The "open powershell here" option was missing in my VW, I don't think it's on by default. EDIT: Oh I have to hold shift while right clicking! My bad.
In case anyone want's to try this, I've uploaded the compiled firmware for the Pico here: https://anonfiles.com/T9L8F8D9u1/firmware_uf2 (circuitpython with changed VID / PID values)
I don’t know what I did to deserve this, but I guess I’ll continue my morning without reading this article?
Given they already have admin rights it's basically game over, but not having the option to open a shell would have still reduced the attack surface and required a "real" exploit to do so.
It’s not admin, it’s NTAuth\SYSTEM, a much much higher privileged account. System is the most powerful account in Windows, bypassing almost any system protection in place such as group policy, privilege and permissions, it can talk out of the box to a DC using the machine account password (this is different to a user password), and essentially become uncontested in a network.
Razer makes a lot of junk. I saw a headset stand with plastic and RGB. I don't know why someone would waste money or a bus port on a 5 dollar part with lights. That said, I do own one of their cameras and it's incredible quality. Corsair and Steel Series are usually my go to's.
What's even worse is that Windows automatically installs some Corsair software, which spams you with an iCue popup: https://imgur.com/0fKRYLT
Edit: I’m genuinely curious about it, as opposed to accusing you of lying.
<ctrl-f>keystrokes
It does mention you can turn it off, but still sounds over the top to me.
"Mouse Usage Statistics. Synapse 2.0 offers a feature of collecting mouse usage statistics, specifically keystrokes, mouse-clicks, wheel-rotations and pointer distance travelled. Such collection of statistics may be turned on or off within Synapse and is under your own control."
Maybe you build it into specific other devices-- the administrator's favourite keyboard or mouse has the admin token, but the $4.99 Dells they hand out to the hoi palloi don't have it.
The database has several entries for Razernon eof which is the only only I've ever seen rated 10.
I come away with the impression that Razer care even leaa about security than Microsoft did in the early days of XP: an utterly unacceptable state to be in over 20 years later.
why non msi based installers still exist in any form in 2021 is a mystery to me.
Razer's UX is horrible on Windows, which is a shame since that's where most of their customers will use their products. The moment you plug in a Razer device, Windows starts downloading a 300mb installer that will prompt you to install the Razer management software each time you reboot/plug in the device. If you deny it, Windows will keep the installer and ask you next time anyways.
Go ahead and make my hardware automatically install software i don’t want. Watch how fast it goes in the dumpster
It's a bit crazy that Windows downloads and install random drivers when plugging in a device when a non-admin user is logged in and that should be fixed but besides this, they also have a way to block the offending driver for a while. Publishing it as a zero-day instead feels a bit irresponsible
(even disconnecting the machine from the internet first and disabling the various automatic driver downloads in GPO wasn't enough to stop it...)