Conversation
Edited yesterday

Today's accomplishment:
Code execution as NT AUTHORITY\SYSTEM, triggered by playing a music file on Windows.

Local environment configuration by a non-admin user required, so this definitely isn't RCE. Just LPE.

If MSRC requires me to provide a video of the exploit, that'll force my hand to drop 0day. 😂

This exploit takes advantage of something I discovered recently combined with a vulnerability that Microsoft decided to only partly fix in July. (The part they decided not to fix was quite useful!)

2
7
0

@wdormann So are you taking requests for the music to play in the video demo?

1
1
0

Fun fact:

If you go to report a vulnerability to MSRC that is a missed-fix or a variant of something that Microsoft has already released an update for, you must provide the existing VULN- identifier. Just a CVE isn't enough, for reasons I cannot fathom. (If you tell Microsoft a CVE ID, they themselves can easily see which VULN- ID is associated with it.)

Meaning, only the person who reports a vulnerability to Microsoft is allowed to tell them that the fix wasn't good enough. (The VULN- ID is what you get when you submit a case to MSRC)

Great job, folks. It instills great confidence when your form for receiving vulnerabilities confuses when to use OR with when to use AND. 🤦‍♂️

4
3
0

@wdormann I bet there's a support for this form that will clear it up, by having copilot alter and regurgitate whatever doc page is the closest to your query

1
0
0

@ferrix
They can look up the VULN- number for any CVE they've handled. It's in their system.

1
0
0

@wdormann That behavior my friend is called CMA (Cover My Ass).

They try to delay as much as they can because if there is a breach with their code included they can always say

“Hey, we didn’t know as nobody has yet reported this vulnerability.”

0
0
0

@tiraniddo @ferrix
I did indeed use VULN-123456. 😂

0
2
0

MSRC is starting well with their "piss off the reporter" strategy.

I reported in full detail a two-vulnerability exploit chain, since on their own either vulnerability is somewhat shrug-worthy. I got a request that I submit a separate report for the second vulnerability.

I dunno, maybe do it yourself? You already have everything. MSRC is a perfect example of an organization where nobody wants to do their job.

1
2
0

@wdormann Microsoft: putting the Computer in “Computer Says No”.

0
1
0
@wdormann What *is* their job though? Incentives are pervese and blurring risk is in many cases the most cost-effective for everyone. If shits hit the fan, they can blame $country or AI (or both).

Somewhat related: who would've predicted that ClickFix will become an actual ItW vector that needs to be mitigated?!
0
0
1