• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
iGuRu

iGuRu

Real-time Technology News. Opinions & Tweaks

  • / news
  • / infosec
  • / tools
  • / tweaks
  • / dummies
  • / opinions
  • / support
home / News / Windows Update: may run malicious programs

Windows Update: may run malicious programs

13/10/2020 19:55 by Anastasis Vasileiadis

LoLBins are executable with a Microsoft signature (preinstalled or downloaded) that can prevent malware from being detected when downloading, installing, or running malicious code.

They can also be used by attackers in their attempts to bypass Windows User Account Control (UAC) or Windows Defender Application Control (WDAC) and gain access to already compromised systems.windows updates - Windows Update: may run malicious programs

WSUS / Windows Update client (wuauclt) is a utility located in % windir% \\ system32 \\ which gives users some control over some of the Windows Update Agent functions from the command line.

Allows you to check for new updates and install them without having to use the Windows user interface, but instead enable them from a command prompt window.

The use of choice  ResetAuthorization Allows you to start a manual update check either on the locally configured WSUS server or through the Microsoft Update service according to Microsoft.

However, MDSec researcher David Middlehurst has discovered that wuauclt can also be used by attackers to execute malicious code on Windows 10 systems by loading it from a specially designed malicious DLL with the following command line options:

wuauclt.exe / UpdateDeploymentProvider [path_to_dll] / RunHandlerComServer

Screenshot 2020 10 13 Windows Update can be abused to execute malicious programs - Windows Update: can run malicious programs

As shown in the screenshot above, Full_Path_To_DLL is the absolute path to the specially constructed DLL file of the attacker that would execute code in the attachment.

This technique is categorized by MITER ATT \ CK as running a binary proxy through Rundll32 and allows intruders to bypass the antivirus program, scan applications, and validate digital certificates.

In this case, it does this by running malicious code from a DLL that was loaded using a Microsoft-signed binary, Windows Update (wuauclt).

After discovering that wuauclt could also be used as LoLBin, Middlehurst also found a sample that used it for online attacks.

Microsoft recently updated its Microsoft 10 Defender antivirus solution to Windows XNUMX by quietly adding a (potentially malicious) way to download files to Windows devices.

Screenshot 2020 10 13 Windows Update can be abused to execute malicious programs1 - Windows Update: can run malicious programs

Microsoft later removed this feature from MpCmdRun.exe (the Microsoft Antimalware Service Line Utility).

Windows Update: may run malicious programs was last modified: October 13, 2020, 7: 55 mm by Anastasis Vasileiadis

Subscribe to our newsletter

no spam

spread the news

  • Facebook
  • Twitter
  • Reddit
  • Printing
  • Email

Read them Technology News from all over the world, with the validity of iGuRu.gr

Follow us on Google News


Competition: NewsDay: Windows update

You May Also Like

.NET Core updates via Windows Update
Windows 10 KB4023057 prepares the system for update
Windows 10 suspend updates due to holidays

About Us Anastasis Vasileiadis

Translations are like women. When they are beautiful they are not faithful and when they are faithful they are not beautiful.

Previous Post: « Krita 4.4.0 Open Source image editing application
Next Post: The only announcement for the new iPhone 12 »

Reader Interactions

Comment Policy:

IGuRu.gr does not publish the comments immediately. Malicious comments, comments that include ads, or comments that are offensive are deleted without notice. We do not adopt the opinions expressed by our readers.
Your comments will be displayed after approval by the administrators


Leave your comment
Ακύρωση απάντησης

Your email address is not published. Τα υποχρεωτικά πεδία σημειώνονται με *

 

 © 2021 · iGuRu.gr · ☢ · Keep It Simple Stupid Genesis theme

about  ·   get in touch  ·  rss  ·  sitemap  ·  cough

loadingCancel
Could not post post - check your email address!
Email verification failed, please try again
Your blog can not post posts via email.