ARE YOU PROTECTED BY GUARDEDID ... ALERT ... SCREWED

New Post Public Reply Private Reply Replies (1) Message Board
CyberC
491
ARE YOU PROTECTED BY GUARDEDID ...

ALERT ...

SCREWED DRIVERS – SIGNED, SEALED, DELIVERED
August 10, 2019 / Eclypsium



INTRODUCTION
Common Design Flaw In Dozens of Device Drivers Allows Widespread Windows Compromise

feature-image-drivers.png

As part of Eclypsium’s ongoing hardware and firmware security research, we have become increasingly interested in the area of insecure drivers and how they can be abused in an attack against a device. Drivers that provide access to system BIOS or system components for the purposes of updating firmware, running diagnostics, or customizing options on the component can allow attackers to turn[img][/img] the very tools used to manage a system into powerful threats that can escalate privileges and persist invisibly on the host.

Recent research and attacks in the wild have made it clear that this area warrants additional scrutiny. For example, other research has revealed vulnerabilities in individual hardware vendor drivers (e.g. ASUS, ASRock, GIGABYTE) that allowed applications with user privileges to read and write with the privileges of kernel. This is obviously a serious escalation of privileges, and we wanted to know if these sorts of vulnerabilities were isolated incidents or examples of a more widespread problem. Secondly, there are multiple examples of attacks in the wild that take advantage of this class of vulnerable drivers. For example, the Slingshot APT campaign installs a kernel rootkit by exploiting drivers with read/write MSR capabilities in order to bypass driver signing enforcement. And the recent LoJax malware abused similar driver functionality to install malicious implants within the firmware of a victim device and persist even across a complete reinstallation of the operating system.

drivers-interlude.png

Our analysis found that the problem of insecure drivers is widespread, affecting more than 40 drivers from at least 20 different vendors – including every major BIOS vendor, as well as hardware vendors like ASUS, Toshiba, NVIDIA, and Huawei. However, the widespread nature of these vulnerabilities highlights a more fundamental issue – all the vulnerable drivers we discovered have been certified by Microsoft. Since the presence of a vulnerable driver on a device can provide a user (or attacker) with improperly elevated privileges, we have engaged Microsoft to support solutions to better protect against this class of vulnerabilities, such as blacklisting known bad drivers.

rings.png

OVERVIEW AND IMPACT OF THE VULNERABILITIES
All these vulnerabilities allow the driver to act as a proxy to perform highly privileged access to the hardware resources, such as read and write access to processor and chipset I/O space, Model Specific Registers (MSR), Control Registers (CR), Debug Registers (DR), physical memory and kernel virtual memory. This is a privilege escalation as it can move an attacker from user mode (Ring 3) to OS kernel mode (Ring 0). The concept of protection rings is summarized in the image below, where each inward ring is granted progressively more privilege. It is important to note that even Administrators operate at Ring 3 (and no deeper), alongside other users. Access to the kernel can not only give an attacker the most privileged access available to the operating system, it can also grant access to the hardware and firmware interfaces with even higher privileges such as the system BIOS firmware.

Ring Privilege Graphic
HOW VULNERABILITIES CAN BE USED IN AN ATTACK
A vulnerable driver installed on a machine could allow an application running with user privileges to escalate to kernel privileges and abuse the functionality of the driver. In other words, any malware running in the user space could scan for a vulnerable driver on the victim machine and then use it to gain full control over the system and potentially the underlying firmware. However, if a vulnerable driver is not already on a system, administrator privilege would be required to install a vulnerable driver.

As mentioned earlier, a vulnerable driver could also give an attacker access to the “negative” firmware rings that lie beneath the operating system. As seen with the LoJax malware, this allows malware to attack vulnerable system firmware (e.g. UEFI) to maintain persistence on the device, even if the operating system is completely reinstalled. The problem extends to device components, in addition to the system firmware. Some vulnerable drivers interact with graphics cards, network adapters, hard drives, and other devices. Persistent malware inside these devices could read, write, or redirect data stored, displayed or sent over the network. Likewise, any of the components could be disabled as part of a DoS or ransomware attack.

Since many of the drivers themselves are designed to update firmware, the driver is providing not only the necessary privileges, but also the mechanism to make changes.

SIGNED AND CERTIFIED DOES NOT MEAN SAFE
It is of particular concern that the drivers in question were not rogue or unsanctioned – in fact, just the opposite. All the drivers come from trusted third-party vendors, signed by valid Certificate Authorities, and certified by Microsoft. Both Microsoft and the third-party vendors will need to be more vigilant with these types of vulnerabilities going forward.

These issues apply to all modern versions of Microsoft Windows and there is currently no universal mechanism to keep a Windows machine from loading one of these known bad drivers. Implementing group policies and other features specific to Windows Pro, Windows Enterprise and Windows Server may offer some protection to a subset of users. Once installed, these drivers can reside on a device for long periods of time unless specifically updated or uninstalled. In addition to the drivers which are already installed on the system, malware can bring any of these drivers along with them to perform privilege escalation and gain direct access to the hardware.


IMPACTS AND MITIGATION
The presence of vulnerable drivers can make it increasingly challenging to secure the firmware attack surface. Vulnerable or outdated system and component firmware is a common problem and a high value target for attackers, who can use it to launch other attacks, completely brick systems, or remain on a device for years gathering data, even after the device is wiped. To make matters worse, in this case, the very drivers and tools that would be used to update the firmware are themselves vulnerable and provide a potential avenue for attack. As a result, organizations should not only continuously scan for outdated firmware, but also update to the latest version of device drivers when fixes become available from device manufacturers.

drivers-interlude.png

Organizations may also want to keep their firmware up to date, scan for vulnerabilities, monitor and test the integrity of their firmware to identify unapproved or unexpected changes.

LIST OF AFFECTED VENDORS
ASRock
ASUSTeK Computer
ATI Technologies (AMD)
Biostar
EVGA
Getac
GIGABYTE
Huawei
Insyde
Intel
Micro-Star International (MSI)
NVIDIA
Phoenix Technologies
Realtek Semiconductor
SuperMicro
Toshiba
Some affected vendors are still under embargo due to their work in highly regulated environments and will take longer to have a fix certified and ready to deploy to customers.

You can read the DEF CON presentation here.

Posted in Research

Zerify Inc (ZRFY) Stock Research Links

ZRFY Board Company Profile Buy Rating Time & Sales News Filings Financials
Scroll down for more posts ▼

Top 10 Most Recent News Articles

Sunshine Silver Names Patterson to Boost Investor Ties

Updated Category News Views 3

Shifts in Silver Mining: A New Face at Sunshine Awright, let's talk silver. No, not paper dollars, but the shiny stuff in the ground. Sunshine Silver Mining & Refining's just brought a guy named Mike Patterson onboard to shake things up with investor relations and corporate strategy. Sunshine's got big plans, you see. They're eyeing the restart of the Sunshine Mine,...

Continue Reading
Exploring Denture to Implant Solutions with Dr. Miller

Updated Category News Views 0

The Changing Face of Tooth Replacement Let's dive into teeth. We're talking dentures, implants, and the rest of the gang that live in the world of full mouth replacements. Dr. Christopher Glenn Miller’s insights shared with HelloNation zero in on the evolution of tooth replacement options. Gone are the days of clunky dentures being your only shot. From sucking gum to...

Continue Reading
Midland Boosts Market Reach With Pegasus Acquisition

Updated Category News Views 1

A Strategic Leap In Connection Products You know, in the business world, it's all about making those smart moves that position you right at the doorstep of growth. Midland Industries is doing just that with its recent acquisition of Pegasus Supply Group. While Midland didn't spill the beans on the financials, this takeover seems more than just a simple grab for assets....

Continue Reading
Safety Tech in Fleets: Drivers Embrace Its Role

Updated Category News Views 0

Drivers Warming Up to Fleet Safety Tech Seems like most fleet drivers these days are eyeing safety tech through a fresher lens. Gone are the days when grumbling about privacy was the anthem of the disgruntled. The latest Linxup survey claims a whopping 77% of commercial fleet pros have hopped onto the safety train, happily trading privacy qualms for the perks of solid...

Continue Reading
Education's Future Explored at Reagan Institute Summit

Updated Category News Views 1

When Second Lady Usha Vance joins a summit, folks know it's a big deal. The Reagan Institute’s Education Summit is shaping up to be a showdown of ideas, tackling education’s role in a whirlwind of technological and political changes. This ain’t your average PTA meeting. We’re talking heavyweights like Utah Governor Spencer Cox and Colorado Governor Jared Polis...

Continue Reading
Tranter's New Press Boosts Vänersborg Operations

Updated Category News Views 1

Tranter's Bold Move in Manufacturing No smoke and mirrors about it—Tranter's pulling out the big guns in Vänersborg with a shiny new 5,000-metric-ton press. And why not? As heat exchangers become hotter commodities, you've got to gear up to meet the demand or watch customers drift. This isn't just a new toy; it's a weapon for dominating growing markets. Precision and...

Continue Reading
Immunic Paves Path with New Digital Leadership

Updated Category News Views 2

Shifting Gears: A Closer Look at Immunic's New Direction It's not every day you witness a biotech outfit like Immunic making waves with a high-profile leadership shift. Today, they introduced Chitrang Davé as their Chief Data and Digital Officer. Why's this a big deal? Well, it's a signal that Immunic is dead serious about stepping into commercial territory. The Role and...

Continue Reading
Adecoagro Expands with Caarapó Mill Acquisition

Updated Category News Views 0

Crushing the Competition: Adecoagro's New Acquisition When there's dirt under your fingernails and deals in the air, taking a strategic swing like Adecoagro just did can be a game-changer. Shelling out R$705 million (roughly US$136 million) in cash isn't what you'd call pocket change, but they're not new to ballsy moves. They've snapped up the Caarapó Mill, previously...

Continue Reading
Get Scared Early: First Fright 2026 Kicks Off!

Updated Category News Views 4

Gearing Up for Sneak-Attack Thrills Look, some folks stock up on candy by October, but the real adrenaline junkies? They’re already on the road long before that, eyes set on hitting America's creepiest haunts. This year, the game isn't just October. Mark the date—September 11 is when the screams start pushing the limits of your vocal cords, thanks to America Haunts....

Continue Reading
Ignyte Insurance Acquires InsureMyTrip to Expand Portfolio

Updated Category News Views 0

Key Acquisition: Strengthening Global Presence Ignyte Insurance just added a major player to its roster with the acquisition of InsureMyTrip. No two ways about it, this move is about expanding their footprint in the booming travel and medical insurance sector. Now, if you've ever thought travel insurance was just fine print nobody reads, think again. This industry’s got...

Continue Reading

Top 5 Most Recently Viewed Articles

VanillaSoft Welcomes New Leadership for Future Growth

Updated Category News Views 191

VanillaSoft Announces Key Leadership Changes Austin, Texas - VanillaSoft, a leading sales engagement technology company, has taken significant steps to enhance its leadership team. The recent appointments mark a strategic move aimed at driving the company’s growth and improving customer experiences. Paul McGee's Promotion to Senior Vice President In an exciting...

Continue Reading
Globe Life, Inc. Highlights Solid Financial Performance Q3 2024

Updated Category News Views 55

Globe Life Reports Impressive Q3 Financial Results Globe Life Inc. (NYSE: GL) recently announced its financial results for the third quarter of 2024, marking significant growth compared to the previous year. The company reported a net income of $3.44 per diluted common share, a notable increase from $2.68 per diluted share in the same quarter of the prior year....

Continue Reading
TechnoMile's Merger: The Future of Government Contractor Solutions

Updated Category News Views 178

TechnoMile’s Path to Growth: A Strategic Merger TechnoMile, an ambitious AI-powered platform for government contractors, has achieved remarkable growth over the years. This incredible journey took a significant leap forward with the recent merger with SIMS Software, a well-respected name in industrial security software. K1 Investment Management, a leading investor in...

Continue Reading
Rigel Pharmaceuticals Grants New Stock Options for Employees

Updated Category News Views 120

Rigel Pharmaceuticals Announces Employee Stock Options Rigel Pharmaceuticals, Inc. (Nasdaq: RIGL) has recently made headlines by granting new stock options to its employees, an action that reflects the company’s commitment to its workforce. This decision was made in alignment with NASDAQ Listing Rule 5635(c)(4), facilitating new employment compensations for the team at...

Continue Reading
Investigation of Applied Therapeutics: Investors Take Action

Updated Category News Views 208

Investigation into Applied Therapeutics, Inc. Recently, concerns have been raised regarding the performance and governance of Applied Therapeutics, Inc. (NASDAQ: APLT). Legal discussions have initiated an investigation focused on possible violations of federal securities laws, dedicated to protecting the interests of investors. Shocking Developments for Shareholders On...

Continue Reading