Homeinet0Day for all Windows (XP - Windows 10 - Server)

0Day for all Windows (XP – Windows 10 – Server)

A security researcher from Colombia has discovered a way (0Day) to gain administrator privileges and boot persistence on any computer running Windows.

The surprising thing is that the technique was first publicly published in December 2017, but was never reported by the media, despite its seriousness. 0Day for all Windows (XP - Windows 10 - Server)

Also, this particular 0Day does not seem to have been taken into account by the malware developers.

The 0Day was discovered by Sebastián Castro, a security researcher at CSL. The exploit targets one of the parameters of Windows user accounts known as the Relative Identifier (RID).

The RID is a code added to the end of each account's security identifier (SID) and describes the user's privilege group. There are many RIDs available, but the most common are 501 for the standard guest account and 500 for administrator accounts.

Castro, with the help of CSL CEO Pedro García, discovered that registry keys store information about each Windows account. From there, he could modify the RID associated with a particular account and assign it a different RID from the Administrators group.

The technique does not allow a hacker to remotely infect a computer unless it is exposed to the Internet without a password.

Of course, we should mention that there are also cases where a hacker can access a system with some malware. In case they gain access with simple user rights, it is very simple to become an administrator with full access to the Windows system.

It should also be noted that registry keys operate immediately upon boot (boot persistence), so any changes made to the account RIDs remain permanent until corrected.

The attack is very reliable. It has been tested and found to work flawlessly on all versions of Windows from XP to Windows 10 and from Server 2003 to Server 2016. Theoretically, older versions should also be vulnerable.

"It's not that easy to detect the exploit, because this attack could be deployed using OS resources without causing any notification to the victim," Castro says.

We can discover the RID attack by examining the [Windows] registry and checking for inconsistencies in the SAM (Security Account Manager).

If the guest account's SID has a RID of 500, the guest account has administrator privileges.

[su_note note_color=”#ebebeb” text_color=”#271e45″ radius=”2″]We should also mention (without suggesting) that this exploit can help you gain an administrator account on systems that have you as a user. [/su_note]

__________________

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS