A vulnerability in Windows that Microsoft addressed with a patch this month allows hackers to steal sensitive files using the built-in Remote Assistance App.
Remote Assistance, which is available by default in Windows, allows users to receive technical support by simply sending an invitation file, which in turn allows a technician to connect to their system simply by running that file and without any other authentication methods.
While the process is quite smooth and is indeed very effective when it comes to providing technical support, it turns out that it leaves the door open to hackers, who may want to extract certain data from a system.
Researcher Nabeel Ahmed discovered a flaw in the XML invitation file, which can be exploited by an attacker to automatically search for a specific file after the connection is established and upload it to a predefined remote server.
Users are generally protected unless they open unknown invitation files.
Since the hacker has to change the configuration data in the XML file and then convince the target to open the invitation, it means that users are pretty much safe if they don't launch files from sources they don't trust. Additionally, hackers can only extract specific files that they know exist on the target system, although this method can also be used for log files and backups.
“To exploit this situation, an attacker would need to send a specially crafted invitation file to a user. The attacker could then steal text files from known locations on the victim’s machine, the user’s content, or alternatively steal text information from URLs accessible to the victim,” Microsoft explains.
“The stolen information could be submitted as part of the URL in HTTP requests to the attacker. In all cases an attacker would not be able to force a user to view the attacker-controlled content. Instead, an attacker would have to convince a user to take action.”
The vulnerability was documented as CVE-2018-0878 and reported to Microsoft last November. An update was released in March 2018 to protect modern systems from exploits targeting this flaw.
