{"id":473657,"date":"2022-12-12T12:52:13","date_gmt":"2022-12-12T10:52:13","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=473657"},"modified":"2022-12-12T12:58:04","modified_gmt":"2022-12-12T10:58:04","slug":"huge-security-flaw-lets-attackers-trick-antivirus-software-into-wiping-legitimate-data","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/473657-huge-security-flaw-lets-attackers-trick-antivirus-software-into-wiping-legitimate-data.html","title":{"rendered":"Huge security flaw let attackers trick antivirus software into wiping legitimate data"},"content":{"rendered":"<p><strong><a href=\"https:\/\/www.safebreach.com\/resources\/blog\/safebreach-labs-researcher-discovers-multiple-zero-day-vulnerabilities\/\" target=\"_blank\" rel=\"noopener\">SafeBreach<\/a><\/strong> cybersecurity researcher Or Yair has found a way to exploit antivirus quarantine features to turn them into data wipers.<\/p>\n<p>Yair managed the feat using endpoint detection and response (EDR) and antivirus (AV) software from Avast, AVG, Microsoft, SentinelOne, and TrendMicro.<\/p>\n<p>The exploit can be used to carry out stealthy attacks and remove the need to be a privileged user to run destructive attacks.<\/p>\n<p>Data wiping attacks carried out by abusing AVs and EDRs can effectively bypass a system&#8217;s defences as the file deletion features of security solutions are expected behaviour and would likely be overlooked.<\/p>\n<p>&#8220;There are two main events when an EDR deletes a malicious file. First, the EDR identifies a file as malicious and then it deletes the file,&#8221; Yair explained.<\/p>\n<p>&#8220;If I could do something between these two events, using a junction, I might be able to point the EDR towards a different path.&#8221;<\/p>\n<div id=\"attachment_473661\" style=\"width: 1210px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2022\/12\/AV-EDR-exploit.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-473661\" class=\"size-full wp-image-473661\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2022\/12\/AV-EDR-exploit.jpg\" alt=\"\" width=\"1200\" height=\"314\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2022\/12\/AV-EDR-exploit.jpg 1200w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2022\/12\/AV-EDR-exploit-600x157.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2022\/12\/AV-EDR-exploit-800x209.jpg 800w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2022\/12\/AV-EDR-exploit-768x201.jpg 768w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><\/a><p id=\"caption-attachment-473661\" class=\"wp-caption-text\">Deleting the malicious directory and creating a junction to point to the target directory<\/p><\/div>\n<p>Yair&#8217;s approach was to create a <em>C:\\temp\\Windows\\System32\\drivers<\/em> folder in which he would store the Mimikatz program as &#8220;ndis.sys&#8221;.<\/p>\n<p>The idea was to have the program detected as malicious when created, at which point Yair would quickly delete the <em>C:\\temp<\/em> folder and create a junction from <em>C:\\temp<\/em> to <em>C:\\Windows<\/em>.<\/p>\n<p>In theory, this would cause the EDR to try and delete the ndis.sys file, which is now pointing to the valid <em>C:\\Windows\\system32\\drivers\\ndis.sys<\/em> file.<\/p>\n<p>However, some EDRs prevented the deletion of the file after it was detected as malicious, while others noticed the deletion of the file, dismissing the wiping action.<\/p>\n<p>Yair solved this by creating the malicious file, holding its handle by keeping it open, and not defining which processes have permission to delete it.<\/p>\n<p>The security tools then prompted a restart to release the handle, freeing the file for deletion.<\/p>\n<div id=\"attachment_473663\" style=\"width: 1210px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2022\/12\/Restart-prompt.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-473663\" class=\"size-full wp-image-473663\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2022\/12\/Restart-prompt.jpg\" alt=\"\" width=\"1200\" height=\"575\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2022\/12\/Restart-prompt.jpg 1200w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2022\/12\/Restart-prompt-600x288.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2022\/12\/Restart-prompt-800x383.jpg 800w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2022\/12\/Restart-prompt-768x368.jpg 768w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><\/a><p id=\"caption-attachment-473663\" class=\"wp-caption-text\">Security software prompts a restart to free the handle for deletion<\/p><\/div>\n<p>&#8220;What&#8217;s surprising about this default Windows feature is that once it reboots, Windows starts deleting all the paths and blindly follows junctions,&#8221; Yair noted.<\/p>\n<p>He found that by using the following process, he could delete files in directories with no modification privileges.<\/p>\n<ol>\n<li>Create a specific path for the malicious file at <em>C:\\temp\\Windows\\System32\\drivers\\ndis.sys<\/em>;<\/li>\n<li>Hold its handle open to force the defence software to postpone deletion until after a reboot;<\/li>\n<li>Delete the C:\\temp directory;<\/li>\n<li>Create the C:\\temp \u2192 C:\\ junction; and,<\/li>\n<li>Reboot when prompted.<\/li>\n<\/ol>\n<p>Yair tested the exploit with 11 security tools and found that Microsoft Defender, Defender for Endpoint, SentinelOne EDR, TrendMicro Apex One, Avast Antivirus, and AVG Antivirus were all vulnerable.<\/p>\n<p>SafeBreach reported the vulnerabilities to the affected vendors in July and August 2022.<\/p>\n<p>&#8220;We then worked closely with them over the next four months on the creation of a fix prior to this publication,&#8221; it added.<\/p>\n<hr \/>\n<h2 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/473167-apple-adds-anti-eavesdropping-feature-to-imessage.html\" rel=\"bookmark\">Apple adds anti-eavesdropping feature to iMessage<\/a><\/h2>\n","protected":false},"excerpt":{"rendered":"<p>A cybersecurity researcher managed to trick six different endpoint detection and response and antivirus products into wiping legitimate files.<\/p>\n","protected":false},"author":341076,"featured_media":473667,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[52915,4698,123,83249,80863,83247,43062],"class_list":["post-473657","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-avast","tag-avg","tag-microsoft","tag-safebreach","tag-sentinelone","tag-trendmicro","tag-windows-defender"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/473657"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341076"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=473657"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/473657\/revisions"}],"predecessor-version":[{"id":473747,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/473657\/revisions\/473747"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/473667"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=473657"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=473657"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=473657"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}