Live data from Hacker News

Microsoft finds privilege escalation vulnerability in Huawei driver

microsoft.com

41–50 of 138 posts

Re: Microsoft finds privilege escalation vulnerability in Huawei driver

#41
post #8

Earlier quoted context omitted.

There is no valid reason, ever, for a driver to do what the Huawei driver did here. That should be obvious given the detection methods that Microsoft implemented in the kernel to find and prevent just this behavior. The Microsoft blog might stop short of calling it malware, but I think we don't need the faux politeness here. The fact that their malware also contained a privilege escalation (the "vulnerability") is me…

I mean, it's goofy, hacky, and has obvious security flaws but doesn't look malicious. Calling it a "backdoor" ascribes a certain intentionality to the vulnerability that's not clear is warranted. It's about the code quality I expect from the management shovelware that comes preloaded on laptops from any major brand. Source: I've written kernel drivers and exploits.

The microsoft article mentions that Windows Defender caught multiple machines performing kernel injections near the same time with this driver as the root cause. Meaning it was already being exploited.

This doesn't mean the actual flaw was malicious, but being actively exploited, it seems intent doesn't really matter.

Re: Microsoft finds privilege escalation vulnerability in Huawei driver

#42

Earlier quoted context omitted.

...because it's the hardware management service and if it goes down you're no longer managing the hardware? Like this stuff is usually designed by EEs and they love their watchdogs at all levels. Having a watchdog is very standard for this stuff.

>...because it’s the hardware management service and if it goes down you’re no longer managing the hardware? I’m no expert on device drivers but to my knowledge, Windows already allows you to manage devices and install drivers through Device Managers. Then if drivers are already installed for the various devices and hardware components, what exactly is the hardware management service managing on top of the individual…

Device Manager only handles kernel drivers. Best practice is to put as much as possible into a highly privileged, but still user mode process so it can crash without bluescreening your system. If you assume that this code can crash (hence why it was delegated to user mode in the first place) it makes sense to code in a resurrection capability.

Re: Microsoft finds privilege escalation vulnerability in Huawei driver

#43
post #8

Earlier quoted context omitted.

There is no valid reason, ever, for a driver to do what the Huawei driver did here. That should be obvious given the detection methods that Microsoft implemented in the kernel to find and prevent just this behavior. The Microsoft blog might stop short of calling it malware, but I think we don't need the faux politeness here. The fact that their malware also contained a privilege escalation (the "vulnerability") is me…

I mean, it's goofy, hacky, and has obvious security flaws but doesn't look malicious. Calling it a "backdoor" ascribes a certain intentionality to the vulnerability that's not clear is warranted. It's about the code quality I expect from the management shovelware that comes preloaded on laptops from any major brand. Source: I've written kernel drivers and exploits.

Have you heard of plausible deniability?

Re: Microsoft finds privilege escalation vulnerability in Huawei driver

#44

Earlier quoted context omitted.

I mean, it's goofy, hacky, and has obvious security flaws but doesn't look malicious. Calling it a "backdoor" ascribes a certain intentionality to the vulnerability that's not clear is warranted. It's about the code quality I expect from the management shovelware that comes preloaded on laptops from any major brand. Source: I've written kernel drivers and exploits.

The microsoft article mentions that Windows Defender caught multiple machines performing kernel injections near the same time with this driver as the root cause. Meaning it was already being exploited. This doesn't mean the actual flaw was malicious, but being actively exploited, it seems intent doesn't really matter.

I don't see anything saying this was being actively exploited; the non malicious use case would set off their scanners on all MateBooks running this driver.

Re: Microsoft finds privilege escalation vulnerability in Huawei driver

#45
post #30

Earlier quoted context omitted.

I mean, it's goofy, hacky, and has obvious security flaws but doesn't look malicious. Calling it a "backdoor" ascribes a certain intentionality to the vulnerability that's not clear is warranted. It's about the code quality I expect from the management shovelware that comes preloaded on laptops from any major brand. Source: I've written kernel drivers and exploits.

What is not malicious about a driver whose pure function (this thing literally has no other value or purpose) is maintaining an invincible NT_AUTHORITY process of their pre-installed management software? And achieving that by allocating a RWX page in services.exe? What are we even doing W^X for? Maybe we have different expectations of what a driver is. Take a look for yourself, even the updated PC Manager Software on…

> What is not malicious

> malicious - adj. - having or showing a desire to cause harm to someone

I'ts goofy, and wouldn't pass a design review that I was a part of, but it isn't "showing a desire to cause harm". It just looks like a rushed design.

> about a driver whose pure function (this thing literally has no other value or purpose)

I see nothing about how this driver doesn't have any other functions.

> is maintaining an invincible NT_AUTHORITY process of their pre-installed management software

Because you want the hardware management process to be resurrected if it fails. They're not gaining anything from an attack perspective by deferring to user mode, the process isn't hidden, and they're already running as a kernel driver so they have full control of the system as it is. In Raymond Chen's parlance, they're already on the other side of the airtight hatch.

> Maybe we have different expectations of what a driver is.

I mean, Minix ascribes it's uptime and reliability to a resurrection server. Is this a much crappier design? Yes. Is it such a bad design that it's malicious? No, that's absurd.

> Maybe we have different expectations of what a driver is.

I expect drivers to defer everything they can to user mode so they don't crash the kernel. That's one of the reasons why APCs exist in the first place.

> Take a look for yourself, even the updated PC Manager Software on their website still has the driver with the goofy shellcode in its installer (no idea if it's just not loaded now):

Oh no, they didn't take that out of their package, but even Microsoft says that they fixed the vulnerability, and quicker than responsible disclosure asks for.

Re: Microsoft finds privilege escalation vulnerability in Huawei driver

#46

Earlier quoted context omitted.

I mean, it's goofy, hacky, and has obvious security flaws but doesn't look malicious. Calling it a "backdoor" ascribes a certain intentionality to the vulnerability that's not clear is warranted. It's about the code quality I expect from the management shovelware that comes preloaded on laptops from any major brand. Source: I've written kernel drivers and exploits.

Have you heard of plausible deniability?

So now every bug on a privilege boundary is a backdoor, because of "plausible deniability"?

Re: Microsoft finds privilege escalation vulnerability in Huawei driver

#47

Earlier quoted context omitted.

I mean, it's goofy, hacky, and has obvious security flaws but doesn't look malicious. Calling it a "backdoor" ascribes a certain intentionality to the vulnerability that's not clear is warranted. It's about the code quality I expect from the management shovelware that comes preloaded on laptops from any major brand. Source: I've written kernel drivers and exploits.

> I mean, it's goofy, hacky, and has obvious security flaws but doesn't look malicious. Plausible deniability. If you were to implement a backdoor for a company, would you write "professionally done" all over it?

So now every bug on a privilege boundary is a backdoor, because of "plausible deniability"?

Re: Microsoft finds privilege escalation vulnerability in Huawei driver

#48
post #32

Earlier quoted context omitted.

Without stating a judgment one way or the other on the organization... Epoch times is run by Falun Gong. The Chinese official government line is that Falun Gong is an extremely dangerous cult that should be repressed. I've seen people on the English language internet intentionally comparing it to Jim Jones, David Koresh, etc. In reality it seems to be more like a Chinese version of Scientology.

Hey, Scientology is about making money, aka apples and oranges. Lots of religious movements and suppression’s would be more apt, try puritans.

From what I've heard, Falun Gong is about making money too. It's basically "hey we'll help you and be real nice to you and help you get back on your feet. Now it's your turn to pay up with donations". Which seems better than scientology, I'd say it's most comparable to mormonism

Re: Microsoft finds privilege escalation vulnerability in Huawei driver

#49
post #6
post #4

Backdoor is such a loaded word to use for a vulnerability. Especially since Huawei is involved. Shame on the person who came up with the title and the reporter who uses the term in the article.

The Epoch Times is a Falun Gong propaganda arm, and Falun Gong is basically Chinese Scientology that the CCP has been trying to stamp out.

What?

Maybe the Epoch Times is biased, but the Falun Gong is nothing like scientology: it has no fees and isn't trying to coerce anyone to join.

It's a minority group that is persecuted by the CCP.

Re: Microsoft finds privilege escalation vulnerability in Huawei driver

#50
post #8
post #4

Backdoor is such a loaded word to use for a vulnerability. Especially since Huawei is involved. Shame on the person who came up with the title and the reporter who uses the term in the article.

There is no valid reason, ever, for a driver to do what the Huawei driver did here. That should be obvious given the detection methods that Microsoft implemented in the kernel to find and prevent just this behavior. The Microsoft blog might stop short of calling it malware, but I think we don't need the faux politeness here. The fact that their malware also contained a privilege escalation (the "vulnerability") is me…

Hanlon's razor - Never attribute to malice that which is adequately explained by stupidity.
Post reply on HN