Windows 10 Devices Open To ‘Full Compromise’ From Huawei PC Driver: Microsoft

This isn’t going to help Huawei make friends and influence people. According to ZDNet, researchers at Microsoft have discovered a buggy Huawei utility that could have given attackers a easy way to undermine the security of the Windows kernel:

Microsoft has now detailed how it found a severe local privilege escalation flaw in the Huawei PCManager driver software for its MateBook line of Windows 10 laptops. Thanks to Microsoft’s work, the Chinese tech giant patched the flaw in January. As Microsoft researchers explain, third-party kernel drivers are becoming more attractive to attackers as a side-door to attacking the kernel without having to overcome its protections using an expensive zero-day kernel exploit in Windows. The flaw in Huawei’s software was detected by new kernel sensors that were implemented in the Windows 10 October 2018 Update, aka version 1809.

The kernel sensors are meant to address the difficulty of detecting malicious code running in the kernel and are designed to detect user-space asynchronous procedure call (APC) code injection from the kernel. Microsoft Defender ATP anti-malware uses these sensors to detect actions caused by kernel code that may inject code into user-mode. Huawei’s PCManager triggered Defender ATP alerts on multiple Windows 10 devices, prompting Microsoft to launch an investigation. […] The investigation led the researcher to the executable MateBookService.exe. Due to a flaw in Huawei’s ‘watchdog’ mechanism for HwOs2Ec10x64.sys, an attacker is able to create a malicious instance of MateBookService.exe to gain elevated privileges. The flaw can be used to make code running with low privileges read and write to other processes or to kernel space, leading to a “full machine compromise.”

Lovely. To be clear, this is a bug as opposed to a back door which is what everyone from national governments to security experts have accused Huawei of building into their products. But I suspect that people who are already suspicious of Huawei are going to take this and spin this as “see you can’t trust Huawei.” Having said that, I have to admit that this isn’t going to help their public image at all as it makes them look less than trustworthy.

Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

This site uses Akismet to reduce spam. Learn how your comment data is processed.

%d bloggers like this: