Today's accomplishment:
Code execution as NT AUTHORITY\SYSTEM, triggered by playing a music file on Windows.
Local environment configuration by a non-admin user required, so this definitely isn't RCE. Just LPE.
If MSRC requires me to provide a video of the exploit, that'll force my hand to drop 0day. 😂
This exploit takes advantage of something I discovered recently combined with a vulnerability that Microsoft decided to only partly fix in July. (The part they decided not to fix was quite useful!)
@wdormann So are you taking requests for the music to play in the video demo?
Fun fact:
If you go to report a vulnerability to MSRC that is a missed-fix or a variant of something that Microsoft has already released an update for, you must provide the existing VULN- identifier. Just a CVE isn't enough, for reasons I cannot fathom. (If you tell Microsoft a CVE ID, they themselves can easily see which VULN- ID is associated with it.)
Meaning, only the person who reports a vulnerability to Microsoft is allowed to tell them that the fix wasn't good enough. (The VULN- ID is what you get when you submit a case to MSRC)
Great job, folks. It instills great confidence when your form for receiving vulnerabilities confuses when to use OR with when to use AND. 🤦♂️
@wdormann I bet there's a support for this form that will clear it up, by having copilot alter and regurgitate whatever doc page is the closest to your query
@ferrix
They can look up the VULN- number for any CVE they've handled. It's in their system.
@wdormann That behavior my friend is called CMA (Cover My Ass).
They try to delay as much as they can because if there is a breach with their code included they can always say
“Hey, we didn’t know as nobody has yet reported this vulnerability.”
@tiraniddo @ferrix
I did indeed use VULN-123456. 😂
MSRC is starting well with their "piss off the reporter" strategy.
I reported in full detail a two-vulnerability exploit chain, since on their own either vulnerability is somewhat shrug-worthy. I got a request that I submit a separate report for the second vulnerability.
I dunno, maybe do it yourself? You already have everything. MSRC is a perfect example of an organization where nobody wants to do their job.
@wdormann Microsoft: putting the Computer in “Computer Says No”.