Live data from Hacker News

Microsoft finds privilege escalation vulnerability in Huawei driver

microsoft.com

61–70 of 138 posts

Re: Microsoft finds privilege escalation vulnerability in Huawei driver

#61
post #30

Earlier quoted context omitted.

I mean, it's goofy, hacky, and has obvious security flaws but doesn't look malicious. Calling it a "backdoor" ascribes a certain intentionality to the vulnerability that's not clear is warranted. It's about the code quality I expect from the management shovelware that comes preloaded on laptops from any major brand. Source: I've written kernel drivers and exploits.

What is not malicious about a driver whose pure function (this thing literally has no other value or purpose) is maintaining an invincible NT_AUTHORITY process of their pre-installed management software? And achieving that by allocating a RWX page in services.exe? What are we even doing W^X for? Maybe we have different expectations of what a driver is. Take a look for yourself, even the updated PC Manager Software on…

Writing "drivers" that do questionable things for even more questionable reasons seems to be par for the course in the Windows ecosystem. If I understand the whole situation correctly, Fortnite installs WHQL certified kernel driver, whose sole purpose is to cause BSOD when LSASS.EXE maps pages from the Fortnite process...

Re: Microsoft finds privilege escalation vulnerability in Huawei driver

#62
post #33

Earlier quoted context omitted.

I guess it's because Defender ATP is basically some kind of cloud-service for security and because everyone is running Windows for everything it's targeted at managers or so. I have no idea how useful it is, but I guess they have some advanced techniques to detect certain attacks (like this one, or the dropped DoublePulsar) - If you have to defend some important Active Directory Setup it's probably not a bad deal. It…

Wow, that Logitech app is crazy huh, they just opened a port from all their Logitech Options users to anyone enabling them to make a remote keylogger. MS must have written a huge exposé on that one, can't seem to find it on their Security site though.

Google writes about the bugs they find, Microsoft writes about the bugs they find. What's strange to you?

Re: Microsoft finds privilege escalation vulnerability in Huawei driver

#63

Earlier quoted context omitted.

Have you heard of plausible deniability?

So now every bug on a privilege boundary is a backdoor, because of "plausible deniability"?

Then what other kinds of software need to use a privilege escalation?

Re: Microsoft finds privilege escalation vulnerability in Huawei driver

#64
post #63

Earlier quoted context omitted.

So now every bug on a privilege boundary is a backdoor, because of "plausible deniability"?

Then what other kinds of software need to use a privilege escalation?

The code is designed to be a privilege _deescalation_. It's already running in kernel mode, and is deferring work to a user mode process.

Re: Microsoft finds privilege escalation vulnerability in Huawei driver

#65
post #62

Earlier quoted context omitted.

Wow, that Logitech app is crazy huh, they just opened a port from all their Logitech Options users to anyone enabling them to make a remote keylogger. MS must have written a huge exposé on that one, can't seem to find it on their Security site though.

Google writes about the bugs they find, Microsoft writes about the bugs they find. What's strange to you?

Meh, I just suspect they're not as forthcoming about bugs they find for their preferred hardware partners no matter how crazily bad they are. Partialism like that makes me distrust them, perhaps my skepticism falls the wrong way here, maybe I'm reading an undercurrent that's not there.

Re: Microsoft finds privilege escalation vulnerability in Huawei driver

#66
post #61
post #30

Earlier quoted context omitted.

What is not malicious about a driver whose pure function (this thing literally has no other value or purpose) is maintaining an invincible NT_AUTHORITY process of their pre-installed management software? And achieving that by allocating a RWX page in services.exe? What are we even doing W^X for? Maybe we have different expectations of what a driver is. Take a look for yourself, even the updated PC Manager Software on…

Writing "drivers" that do questionable things for even more questionable reasons seems to be par for the course in the Windows ecosystem. If I understand the whole situation correctly, Fortnite installs WHQL certified kernel driver, whose sole purpose is to cause BSOD when LSASS.EXE maps pages from the Fortnite process...

Is that an anti-cheat feature?

Re: Microsoft finds privilege escalation vulnerability in Huawei driver

#69
post #33

From scanning the page it sounds like Huawei used a hack to make their MateBookService unkillable, unremovable, by unhooking in to services.exe. That in the process of that they left the possibility that the device they were using HwOs.*\.sys was only protected from being used by checking the program had the right path, thus leaving it open to crackers (it being basically g+rw) to use to get the ring-0 permissions ne…

I guess it's because Defender ATP is basically some kind of cloud-service for security and because everyone is running Windows for everything it's targeted at managers or so. I have no idea how useful it is, but I guess they have some advanced techniques to detect certain attacks (like this one, or the dropped DoublePulsar) - If you have to defend some important Active Directory Setup it's probably not a bad deal. It…

I just looked into that Logitech issue, it's interesting to note that contact was made with Logitech engineers in September. The engineers provided assurance that the issue was understood and would be fixed. Months pass... updates were released, none of which contained the security fix. December arrives and finally the vulnerability is made public, picked up by the media, and Logitech releases a fix within days.

It's a familiar pattern. If a large company were a biological organism, one of it's main pain signals would be negative PR. Prod the beast in other ways and it doesn't respond.

Re: Microsoft finds privilege escalation vulnerability in Huawei driver

#70
post #32

Earlier quoted context omitted.

Hey, Scientology is about making money, aka apples and oranges. Lots of religious movements and suppression’s would be more apt, try puritans.

From what I've heard, Falun Gong is about making money too. It's basically "hey we'll help you and be real nice to you and help you get back on your feet. Now it's your turn to pay up with donations". Which seems better than scientology, I'd say it's most comparable to mormonism

Sounds like everybody on this list: https://en.wikipedia.org/wiki/Chinese_lists_of_cults

As far as I know, among them, Falun Gong and The Church of Almighty God was making false promise about their ability of "getting people back on their feet".

I don't know why people here are suddenly on fire when saw me put Falun Gong and cult together. In China, we use word "神棍"[0] to describe someone who fake their supernatural ability and pretend to be the messenger of god. And the word was come out before CCP even a thing, that alone can tell you something does it?

[0] https://zh.wikipedia.org/wiki/%E6%A3%8D%E9%A8%99#%E7%A5%9E%E...

Post reply on HN