HomeSecurityHackers exploit popular plugins to compromise systems

Hackers exploit popular plugins to compromise systems

Plugins: Whether you're a programmer, designer, or writer, a good word processor always helps you save time and work more efficiently.

Additionally, complex word processors provide users with the ability to extend, allowing them to install and run third-party plugins to expand its functionality and, importantly, its scope.

However, it is known that third-party plugins always carry a significant risk of hacking, whether it is WordPress or Windows' extensions for Chrome, Firefox or Photoshop.

Dor Azouri, a researcher at SafeBreach, analyzed several popular text editors for Unix and Linux systems, including Sublime, Vim, Emacs, Gedit, and pico/nano, and found that except for pico/nano, all are vulnerable to a critical privilege escalation that could be used by hackers to execute malicious code on victims' systems.

The issue lies in the way text editors load plugins. According to the researcher, there is insufficient separation of normal and enhanced functionality when loading plugins.plugins

The integrity of folder permissions is not fully maintained, which allows hackers with simple user permissions to escalate their privileges and execute arbitrary code on the target machine.

Therefore, hackers could spread a malicious extension for vulnerable text editors, enabling them to execute malicious code with elevated privileges, install malware, and gain full control of targeted computers.

Azouri suggests that Unix users can use an open source intrusion detection system, called OSSEC, to actively monitor system activity, file integrity, logs, and processes.

Users should avoid loading third-party plugins when the processor is considered “elevated” and also deny write permissions to “non-elevated users”.

Azouri recommended that word processor developers change folder and file permission models to complete the separation between regular and enhanced features and provide a manual interface that allows users to approve increased plugin loading.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS