HomeSecurityThe code for the Bluekeep exploit has been released

Bluekeep exploit code released

  • BlueKeep is a wormable security vulnerability in Microsoft's Remote Desktop Services that allows hackers to remotely take control of vulnerable systems.
  • The developers of Metasploit released the first functional prototype of the exploit code with payload execution capabilities.
  • Bitdefender examined the recently published exploit Bluekeep code and the Introspection Hypervisor blocks this attack

Last Friday, security researchers working on the Metasploit released the first working exploit code to achieve code execution against systems vulnerable to BlueKeep. This high-impact vulnerability affecting Microsoft was first reported as CVE-2019-0708 in May 2019. On May 14, Microsoft began releasing patches for affected Windows operating systems.

The exploit is not yet 100% reliable in remote code execution. Targeted systems may encounter a BSOD during payload execution. However, it is reliable enough to confirm that the kernel protection of Bitdefender Hypervisor Introspection (HVI) released in 2017 essentially defeated BlueKeep. At that time, the vulnerability and the exploit were not known to the public and would have been prevented as a 0-day.

Bluekeep

Why is BlueKeep so dangerous?

BlueKeep is one of those high-severity security flaws that are considered “wormable.” These vulnerabilities are typically bugs in widely used operating system that are typically exposed to the outside world by system administrators and enabled by security teams. Hackers are looking to exploit vulnerabilities found in widely exposed services to maximize and automate the attack surface they are building. To make matters worse, successful attacks gain complete control of the system, as the exploited RDP component is a Windows kernel driver.

There have been several high-profile ransomware attacks in recent years. WannaCry is a fairly recent high-profile worm attack that exploits the EternalBlue vulnerability to spread ransomware. Months before WannaCry hit, we wrote about how Bitdefender Hypervisor Introspection overcame the EternalBlue exploit.

How does Hypervisor Introspection prevent exploitation?

Bitdefender’s Hypervisor Introspection (HVI) is a state-of-the-art anti-exploit technology that uses the Virtual Machine Introspection APIs, built into modern hypervisors, to monitor the entire memory footprint of running VMs. This allows the technology to focus on identifying attack techniques during operation in memory, rather than looking for past behaviors. Hypervisor Introspection does not require prior knowledge of the vulnerability or where it is, and it does not require prior knowledge of the exploit code.

Kernel exploits like BlueKeep (and EternalBlue) require careful actions to gain access to the APIs . When the initial code execution is obtained, the exploit cannot do much without calling operating system functions, since it is executed in an arbitrary environment that will freeze or crash the system. To “migrate” to a known environment, the malicious code will try to intercept the OS SYSCALL handler. Hypervisor Introspection monitors the operating system kernel structures, including the specifications of specific CPU, preventing malicious changes. In this way, Hypervisor Introspection provides general protection against entire classes of attacks that rely on the same exploitation technique.

Hypervisor Introspection is available today for Citrix Hypervisor environments and as part of a technical preview program for organizations that operate with the KVM hypervisor.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS