Windows 0-day drops the identical day Microsoft releases record variety of patches

“If I can arrange the system in order that it runs my code when the admin user logs in,” the attacker has de facto administrator privileges, Will Dormann, a senior principal vulnerability analyst at Tharros Labs, said in an interview. “I don’t should be an admin myself.”

In a post, he said that “the power of a non-admin user to find a way to switch the classes registry hive of an admin user is a reasonably powerful primitive. Clever attackers or individuals who want to perform something will easily find a way to determine do things which are more interesting and/or don’t even require user interaction.”

Dormann said that the exploit could possibly be chained to a separate one that provides direct access to an administrative account.

As explained in a post by a special analyst: “When a brand new user is logging on, Windows must load the user’s class hive. Because the user isn’t logged on before logging on (tautology, I do know), it might’t be loaded within the context of the user. So it’s loaded within the context of NT AUTHORITYSYSTEM. LegacyHive abuses this.”

In an emailed statement, Microsoft said it’s aware of the vulnerability report and is investigating. The corporate also noted its preference that vulnerability reporters follow a coordinated disclosure policy.

For now, Windows users who need to protect their systems against HiveLegacy can run a detection script published by independent researcher Kevin Beaumont. Other defenses are to limit local non-user account creation, monitor ProfSvc for unexpected hive loads, and track NTUSER.DAT/UsrClass.dat activity.

Related Post

Leave a Reply