Windows 10 RCE: The exploit is in the link
positive.security
positive.security
I recently ran into a similar issue with MSRC. I reported two exactly similar(near perfect) heap overflows exploitable from a local perspective with some time in between. The first report was awarded the maximum payout, and patched as 'Important'.
Meanwhile, MSRC changed its rules related local exploitation. Now, to obtain that, one needs to show the exploit working in the most hardened sandbox processes on the system. From my perspective this is quite unfair, both bugs are reported with the same severity to Microsoft's own customers. Both breach about 3 defined security boundaries (process, session and user). So, my communication stayed the same (all technical details), Microsoft's communication with _their_ customers stayed the same (important severity issue, 7.8 cvss), the only thing changed was my reward...(reason: ohh, it's not a sandboxed process, to we don't care.).
The only way to obtain the maximum payout is this even more stringent, and new, requirement of 'sandboxed process' -> 'other user' boundary. As if there are not a hundred thousand organizations sharing machines between users using Citrix and terminal and other similar technologies...
In any case, given that it takes close to a year, with hundreds of hours invested to uncover such a bug... I'm going to take my submissions elsewhere...
Under the old rules that's already 4x as much as MS, but the warm fuzzies made up for that I suppose. Under the new rules, 40x as much, and no warm fuzzies are worth that imo.
> Selling exploit code hurts people.
As providing backdoors for state agents like Microsoft and other companies do.
I'm ignorant on the matter but is Zerodium a black market? As far as I know they might be selling any exploits to the affected companies.
Yeah, I don't like windows either, but its not the point. Billions rely on the security of Windows today, our entire global economy is dependent on reliability of our information systems.
One either helps maintain the security of our systems globally, or they seek to disrupt it for a pay day. I get quite upset when people enter with the mindset of 'the actual vendor wont pay me enough, ill sell it to shady exploit market'. It is not a simple pay day.
Microsoft seems uninterested in fulfilling that responsibility, therefore the responsible thing to do is to "motivate" Microsoft.
Unless you work for free, you don't get to criticize others for getting paid for their work.
This is completely ridiculous. By this reasoning we shouldn’t criticize corrupt politicians or anyone whose chosen profession means they get paid to make the world a worse place to live. I don’t think we’ll see eye to eye on any of this, I simply can’t understand any of the arguments you’ve presented to justify getting paid to make the world a more dangerous place.
I think that when security problems in Microsoft products are Microsoft's responsibility and no one else's. By insisting that other people work for free to improve that security, you're arguing that other people are responsible for said security problems.
That's a curious position. You think that someone who isn't paid is responsible, but not Microsoft, who is paid.
I understand why Microsoft would like that arrangement, but why do think that anything else is wrong?
Sounds like they sell it to the NSA/CIA/FBI so it's used for "national security" and not ransomware worms.
So they wrote a protocol-handler bound on every Win10 machine which arbitrarily runs a command if you can convince the user to click one message box.
Don't all protocol handlers invoke some execution? Like http goes to my browser (only Edge) and that other windows internal one which also goes to Edge (and resets my registered http handler)
Sure, but you don't expect arbitrary code execution. The important distinction is whether the attacker can control what is executed. So if you click on a HTTPS link, you should be safe to assume that it opens a new browser tab, and not open a command prompt like in that example.
Nobody said URL handlers should offer any security guarantees. There is no clear amount of things that a clicked URL should be able to do. In some circumstances, the full permissions of the logged in user would be appropriate.
The security onus really ought to be on the application which sourced the URL - it knows where it came from.
> Exploitation through other browsers requires the victim to accept an inconspicuous confirmation dialog.
No confirmation needed with Windows 10 and IE11 or Edge Legacy
> One of the largest IT Company on this planet, with software running on billions of devices, even in critical infrastructure, would like you to sell exploits to their programs to the open market instead of their bug bounty program.
This isn't a particularly sophisticated or novel attack vector, difficult as it was to find; it's the sort of injection attack caused by string interpolation that should have been caught long before anything was shipped.
[1]: https://www.xda-developers.com/microsoft-breaks-windows-11-b...
Likewise, every Electron app needs to scan its own command-line arguments and refuse to start if...basically anything... is set. It is Unfortunate that Electron in its default configuration allows so many plainly unsafe parameters (--proxy-server also an insanely dangerous one).
In MS Edge you _might_ see a popup window This site is trying to open LocalBridge. A website wants to open this application. <open><cancel>
Other forms of URI in Windows 10 taken from https://www.tenforums.com/tutorials/78214-settings-pages-lis... So paste the below into your Browser ms-settings:nightlight In MS Edge you will see a popup saying This site is trying to open Settings. A Website wants to open this application. <Open><Cancel>
Not knocking the research effort was this found using some automation fuzzing? And are many people still using IE11/Edge Legacy ?
Are there any community patches for this since microsoft has failed to patch what appears to be a 0 day (especially for windows 10)?
The underlying argument injection in LocalBridge.exe (which is the binary processing the JSON payload) is still present, which can be exploited to open other office apps with injected command line arguments. Someone might find another way to run arbitrary code using command line switches other than --gpu-launcher
Teams is not default in Windows (at least my install) - I don't have it and when I have to do meetings in Teams and I am on my Windows machine I just open the meeting in Chrome.
If you don't have Teams yet, you are either in another rollout, you have done something to prevent it or your PC is managed by someone who have prevented it somehow. I think that covers all.
As for why I only use Windows now and then and since I have had a habit of supporting others I keep my personal Windows PCs as plain as possible so I can see what others suffer (obviously I remove nagware like McAfee and make sure spyware like Chrome isn't set as default browser but I have gone as far as to voluntarily run my PC with Norwegian language).
It is a bit tongue in cheek (since I am Norwegian) but only a bit since it is an extra hassle to try to mentally translate what translaters read in English when they created the unsearchable phrases that show up in a localized Windows version.
At home, I want to game and I want to use photoshop.
Both kinda leave me stuck with windows. I could go windows at work and mac at home. But that would require me learning mac, trying to game on mac, replacing a self-build PC with either an M1 chip in a mac-mini / imac. Or with an actual laptop when I only really need a desktop.
All whilst I really like linux. I am stuck using either Windows or Windows and Mac.
edit: I was super lazy and didn't want to troubleshoot that day so I just ran Windows in VM insted.
If anything, gaming blocks a mac more than it blocks linux for me.
https://www.cvedetails.com/product/47/Linux-Linux-Kernel.htm...
Or macOS probably?