Windows Defender could be tricked into deleting databases

microsoft, windows defender could be tricked into deleting databases

Windows Defender could be tricked into deleting databases

Microsoft and Kaspersky’s security products can be tricked into deleting legitimate files, possibly bricking entire applications, experts have warned.

Cybersecurity researchers from SafeBreach discussed their findings during the Black Hat Asia conference in Singapore, The Register reports.

However, not everyone agrees with the researchers, and while Microsoft did acknowledge their findings to some extent, it ultimately decided not to pursue them any further.

To patch or to rebuild

The researchers – Timer Bar and Shmuel Cohen – explained that the problem stems from the fact that both Microsoft and Kaspersky use byte signatures to detect malware. Byte signatures, The Register explains, are unique sequences of bytes in file headers, and should a hacker add them to a legitimate file, the security solutions will flag them as malicious.

In theory, hackers would be able to delete people’s files remotely. For example, they could register as a new user on a website and add the byte signature to their name. The signature would make it into the database, tricking the security program to delete the entire thing. In another example, an attacker could add the signature to a comment of a video.

All of this seems to be theoretical, because the potential consequence is so great that the researchers couldn’t bring themselves to try it out:

“We thought: ‘All Azure clouds are run with Microsoft products and Defender exists on Azure. We really thought that we can attack Azure cloud with this attack, but we were really scared to try it because we don’t know the implication. We could really destroy a production database all over the world, and this could be irreversible. So we were really scared to try to do it ourselves,” The Register cited the researchers.

Initially, Microsoft acknowledged the findings. The vulnerability was registered under CVE-2023-24860, and patched in April 2023. Kaspersky, on the other hand, didn’t release a patch because “the product’s behavior is more driven by design.” It was “planning some improvements to mitigate this issue,” though.

The researchers didn’t fully stop there. Both Kaspersky and Microsoft’s solutions worked at face level, but they wanted to dig deeper. They deemed Kaspersky not popular enough to warrant further investigation, so they focused on Microsoft.

They managed to work around the initial patch, triggering the creation of CVE-2023-3601 in December 2023. They tried again, apparently succeeding to bypass the fix, but this time – Microsoft wasn’t phased, claiming that the bypass only works on already compromised endpoints.

A “bypass of a defense-in-depth security feature by itself does not pose a direct risk as an attacker must also have found a vulnerability that affects a security boundary or they must rely on additional techniques such as social engineering to achieve the initial stage of a device compromise.”

The researchers concluded that, in order to fully address this problem, Defender should be redesigned from the ground up.

More from TechRadar Pro

    News Related

    OTHER NEWS

    Lawsuit seeks $16 million against Maryland county over death of pet dog shot by police

    A department investigator accused two of the officers of “conduct unbecoming an officer” for entering the apartment without a warrant, but the third officer was cleared of wrongdoing, the suit says. Read more »

    Heidi Klum shares rare photo of all 4 of her and Seal's kids

    Heidi Klum posted a rare picture with husband Tom Kaulitz and her four kids: Leni, 19, Henry, 18, Johan, 17, and Lou, 14, having some quality family time. Read more »

    European stocks head for flat open as markets struggle to find momentum

    This is CNBC’s live blog covering European markets. European markets are heading for a flat open Tuesday, continuing lackluster sentiment seen at the start of the week in the region ... Read more »

    Linda C. Black Horoscopes: November 28

    Nancy Black Today’s Birthday (11/28/23). This year energizes your work and health. Faithful domestic routines provide central support. Shift directions to balance your work and health, before adapting around team ... Read more »

    Michigan Democrats poised to test ambitious environmental goals in the industrial Midwest

    FILE – One of more than 4,000 solar panels constructed by DTE Energy lines a 9.37-acre swath of land in Ann Arbor Township, Mich., Sept. 15, 2015. Michigan will join ... Read more »

    Gaza Is Falling Into ‘Absolute Chaos,’ Aid Groups Say

    A shaky cease-fire between Israel and Hamas has allowed a surge of aid to reach Palestinians in Gaza, but humanitarian groups and civilians in the enclave say the convoys aren’t ... Read more »

    Bereaved Israeli and Palestinian families to march together in anti-hate vigil

    Demonstrators march against the rise of antisemitism in the UK on Sunday – SUSANNAH IRELAND/REUTERS Bereaved Israeli and Palestinian families will march together as part of an anti-hate vigil on ... Read more »
    Top List in the World