Author Topic: Windows plagued by 17-year-old privilege escalation bug  (Read 10124 times)

0 Members and 1 Guest are viewing this topic.

Hermite15

  • Guest
Windows plagued by 17-year-old privilege escalation bug
« on: January 20, 2010, 12:44:08 PM »
Quote
Windows plagued by 17-year-old privilege escalation bug
All 32-bit versions vulnerable
Quote
A security researcher at Google is recommending computer users make several configuration changes to protect themselves against a previously unknown vulnerability that allows untrusted users to take complete control of systems running most versions of Microsoft Windows.

The vulnerability resides in a feature known as the Virtual DOS Machine, which Microsoft introduced in 1993 with Windows NT, according to this writeup penned by Tavis Ormandy of Google. Using code written for the VDM, an unprivileged user can inject code of his choosing directly into the system's kernel, making it possible to make changes to highly sensitive parts of the operating system.

"You can in theory write to memory segments that are otherwise considered highly trusted and sensitive," said Tom Parker, a director in the security consulting services group at Securicon, a Washington, DC-based security practice. "So for example, malware could possibly use it to install a key logger."

The vulnerability exists in all 32-bit versions of Microsoft OSes released since 1993, and proof-of-concept code works on the XP, Server 2003, Vista, Server 2008, and 7 versions of Windows, Ormandy reported. Presumably, Windows 2000 is also susceptible. Immunity, a Miami-based company that makes auditing software for security professionals, has already added a module exploiting the vulnerability to its product called Canvas. The exploit has been tested on all versions of Windows except for 3.1.

http://www.theregister.co.uk/2010/01/19/microsoft_escalation_bug/

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Windows plagued by 17-year-old privilege escalation bug
« Reply #1 on: January 20, 2010, 04:16:23 PM »
Hi Logos,

It is a 16 bit kernel exploit in Windows kernel versions since 1993. Advisory to be found here:
http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0346.html
This is believed to affect every release of the Windows NT kernel, from
Windows NT 3.1 (1993) up to and including Windows 7 (2009).
Again another example of security through obscurity, new exploitable skeletons are to be found up inside the Windows cupboard every once in a while, because one has build layer on layer to make it more secure, sometimes flaws are found that are there from day one to the present day, also heap spray exploits with of course javascript as the route will be found again and again. This is a predictable ongoing phenomenon...
Until script blocking like NS in Firefox does reach the MS browser for instance, it will never be fully secure, I fear,

polonus




Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Hermite15

  • Guest
Re: Windows plagued by 17-year-old privilege escalation bug
« Reply #2 on: January 20, 2010, 04:21:13 PM »
hi Polonus,

thanks for the details  ;) ... I still believe that the general switch to NT with XP was the best thing MS could do. Win9x was a disaster of instability and relative insecurity (relative because we were on dial-up, we were not constantly connected, there were not so many web threats etc...... ) thinking that some desktop features in Win95 depended on the presence of IE4 for instance...
« Last Edit: January 20, 2010, 04:29:39 PM by Logos »

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48561
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Windows plagued by 17-year-old privilege escalation bug
« Reply #3 on: January 20, 2010, 04:54:03 PM »
Quote
Win9x was a disaster of instability
I found 98 SE pretty stable. :)  (not very secure your right.)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Hermite15

  • Guest
Re: Windows plagued by 17-year-old privilege escalation bug
« Reply #4 on: January 20, 2010, 04:59:05 PM »
Quote
Win9x was a disaster of instability
I found 98 SE pretty stable. :)  (not very secure your right.)

As to Win9x, I've only been running 95 and 98 (first edition)... I admit 98 was a bit more stable than 95, just a bit...real stability really came with Win2000 and XP (can't tell about WinNT in the 90's...just read a few times it was stable, but very unfriendly, never run it)

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Windows plagued by 17-year-old privilege escalation bug
« Reply #5 on: January 20, 2010, 06:56:02 PM »
Hi Logos and bob3160,

And no-one mentioned ME (how quickly people do forget),


polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48561
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Windows plagued by 17-year-old privilege escalation bug
« Reply #6 on: January 20, 2010, 07:01:54 PM »
Hi Logos and bob3160,

And no-one mentioned ME (how quickly people do forget),


polonus
I didn't forget but my comment was related to stability and Windows ME was never stable.  :'(  ;D ;D
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Hermite15

  • Guest
Re: Windows plagued by 17-year-old privilege escalation bug
« Reply #7 on: January 20, 2010, 07:09:30 PM »
No I didn't forget ME, but I wouldn't have used it even if paid for it  ;D .. ME appears to me as a non-event in Win9x history... same goes for 98 and 98SE btw ... I did buy Windows 98, although I knew in advance that it wouldn't change much compared to Win95...but hey stupidly I wanted the last version  ::), just in case  ::) , but I won't complain, I was an aware victim  ;D :D ... a new PC came after that with XP.
« Last Edit: January 20, 2010, 07:13:08 PM by Logos »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Windows plagued by 17-year-old privilege escalation bug
« Reply #8 on: January 20, 2010, 08:26:21 PM »
Hi Logos,

And the multi-exploits keep returning in PDF, Adobe and for IE. Just Google for and do some background about this heap spray file invalid array stack overflow one dating from 2006:
IE #Address of shellcode printf "\x41\x41\x41\x41" # 
This is due to the software architectural limitations....
 "$page = $page . “\x41\x41\x41\x41″ x 65535;" Just set the executable to a ceratin instruction address .Then, the instruction “call ecx” is executed so the flow of execution will jump to it......
iframe src="file://BBBBBBBBBB....." name="CCCCCCCCCC....." exploit crashed IE then...
Read this that resurfaced again: http://sf-freedom.blogspot.com/2006/07/heap-spraying-internet-exploiter.html

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Hermite15

  • Guest
Re: Windows plagued by 17-year-old privilege escalation bug
« Reply #9 on: January 20, 2010, 08:59:53 PM »
Hi Polonus,

thanks for the additional info but all this coding is "Chinese" to me  ;D (it might actually be  :D )...could you translate into simple non-coder language, would be much appreciated, thanks  ;)

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Hermite15

  • Guest
Re: Windows plagued by 17-year-old privilege escalation bug
« Reply #11 on: January 20, 2010, 09:41:04 PM »
off topic: why doesn't my new avatar show any animation here  ???  :'(

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Windows plagued by 17-year-old privilege escalation bug
« Reply #12 on: January 20, 2010, 09:50:14 PM »
off topic: why doesn't my new avatar show any animation here  ???  :'(

You didn't feed Chompy enough flies and he died?

     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Hermite15

  • Guest
Re: Windows plagued by 17-year-old privilege escalation bug
« Reply #13 on: January 20, 2010, 09:54:27 PM »
lol, yeah...last time I used a gif here the animation worked  ??? ...I'm hijacking the thread I started  ;D  :-X

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Windows plagued by 17-year-old privilege escalation bug
« Reply #14 on: January 20, 2010, 10:06:26 PM »
Apng's don't work as avatars, or at least Chompy doesn't- maybe he's too big.
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog