USB stick-sploit makes anyone a Windows admin

Powered by SC Magazine
 

Windows 7 affected.

Researchers have detailed a current vulnerability in Windows 7 that allows school kids, university students and other local users to side-step security controls and gain administrator access.

The low-severity NULL pointer dereference bug focused on the "rather complex and still largely unexplored" NTFS file system which was exploited via a crafted USB volume.

Gynvael Coldwind found the vulnerability while Mateusz "j00ru" Jurczyk wrote the exploit.

Together, they said it served as an interesting case study of Windows kernel exploitation using novel techniques to achieve reliable code execution with escalated privileges.

"Windows actively uses so many interesting system structures (in)directly controlled from user-mode that there is always one that fits properly, even for very complicated types of memory corruption conditions," the researchers wrote.

"...The only scenario in which it might be a problem security-wise is a local computer shared between multiple users with restricted privileges and thus has been rated as low-severity by both us and MSRC (Microsoft Security Response Center)."

They said the exploit might work on earlier Windows operating systems but did not reproduce on Windows 8.

Microsoft was reportedly investigating a potential fix for stability purposes.

Technical details on the bug and exploit were available on both Coldwind's and Jurczyk's blogs.

Copyright © SC Magazine, Australia


USB stick-sploit makes anyone a Windows admin
 
 
 
Top Stories
ANZ looks to life beyond the transaction
If digital disruptors think an online payments startup could rock the big four, they’ve missed the point of why people use banks, says Patrick Maes.
 
What InfoSec can learn from the insurance industry
[Blog post] Another way data breach laws could help manage risk.
 
A ten-point plan for disrupting security
[Blog post] How can you defend the perimeter when it’s in the cloud?
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Pass on carbon tax savings, warns ACCC
Jul 24, 2014
The ACCC is warning businesses that supply "regulated goods" to pass on any cost savings ...
Have customers that won't pay debts?
Jul 10, 2014
The ACCC and ASIC have updated their advice when it comes to collecting debts.
Carpet cleaner faces court over online testimonials
Jul 4, 2014
The ACCC has initiated proceedings against A Whistle (1979) Pty Ltd, the franchisor of Electrodry...
You can now get 15GB of free online storage using Microsoft OneDrive
Jun 25, 2014
Cloud storage has reached both the capacity and price where it's a viable alternative to local ...
Another clever trick you can perform with Xero
Jun 25, 2014
Here is another way to reach out to particular subsets of your customers using Xero.
Latest Comments
Polls
What is delaying adoption of public cloud in your organisation?







   |   View results
Lock-in concerns
  29%
 
Application integration concerns
  3%
 
Security and compliance concerns
  27%
 
Unreliable network infrastructure
  9%
 
Data sovereignty concerns
  21%
 
Lack of stakeholder support
  3%
 
Protecting on-premise IT jobs
  4%
 
Difficulty transitioning CapEx budget into OpEx
  3%
TOTAL VOTES: 1029

Vote