HomeSecurityWindows: higher level of network access without password

Windows: higher level of network access without password

Windows feature or flaw? Alexander Korznikov, a security researcher, has published a way that helps you gain the highest level of access to a network, without needing a password.

The researcher reported in a blog post that a privileged user, such as a local administrator with system privileges, can use the command line to hijack the session of another logged-in user who has higher privileges.

Windows

Korznikov said that his technique is not just for gaining access to an account with higher privileges, but can also be used by system administrators to gain access to accounts with lower privileges.

The researcher states:

“A bank employee has access to a billing system and his credentials to log in. One day, he has started using the billing system and during his break, he locks his workstation. The system administrator can then log in to the employee’s workstation. According to the bank’s policy, the administrator should not have access to the billing system, but with two built-in Windows commands, the administrator can hijack the employee’s account, which is still locked. Thus, the administrator can perform malicious actions in the billing system through the employee’s account.”

All it takes is about half a minute, according to the PoC video published by the researcher.

https://www.youtube.com/watch?v=VytjV2kPwSg

Korznikov said he tested the bug on systems running Windows 7, Windows 10, Windows Server 2008, and Windows Server 2012 R2, and it works on every supported version of Windows.

Korznikov did not report the matter to Microsoft.

“Everything is done with built-in commands. Any administrator can impersonate any logged-in user either locally with physical access or remotely via Remote Desktop,” he said.

“Reporting to Microsoft can take six months to resolve the issue, and I wanted to let everyone know as soon as possible.”

A Microsoft spokesperson said the alleged flaw “is not a security vulnerability, as it requires local administrator privileges on the machine.”

Feature or flaw? The researcher himself has titled his publication “0-day or Feature? Privilege Escalation / Session Hijacking All Windows versions.” Whether it is or the usefulness of the PoC you watched is up to you to judge.
However, if you consider the scenario with the bank that the researcher describes, malicious actions can very well be caused, without the consent of the account holder.

0-day or Feature

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS