HomeSecurityDell driver patch allows kernel attacks on Windows

Dell driver fix allows kernel attacks on Windows

In May 2021, a set of five vulnerabilities in Dell computer driver programs, collectively referred to as CVE-2021-21551, were disclosed and patched after remaining exploitable for 12 years.

See also: Steve Jobs wanted Dell to pre-install Mac OS on PCs and pay millions

Dell

However, Dell's patch was not comprehensive enough to prevent additional exploitation, and as security researchers are now warning, they may still be an easy target for future Bring Your Own Vulnerable Driver (BYOVD).

"We found that the Dell update did not fix the write-what-where condition, but simply restricted access to administrators. According to Microsoft's definition of security boundaries, the Dell fix removed the security issue," explains Rapid7 researcher Jake Baines.

BYOVD is an abbreviation for “Bring Your Own Vulnerable Driver,” an attack in which malicious actors install a legitimate but vulnerable driver program on a target machine.

This vulnerable driver is then exploited to escalate privileges or execute code on the target system.

It's a well-known technique that has been widely deployed for many years. Unfortunately, even though Microsoft has tried to mitigate the problem with stricter Windows DSE (Driver Signature Enforcement) rules, the problem persists.

There are at least four open source exploits that allow attackers to load unsigned drivers into the Windows , and one of them, KDU, supports more than 14 driver options.

See also: Dell SupportAssist: Bugs expose 30 million PCs to attacks

Based on this alone and without even considering custom tools created by sophisticated hackers and used privately and exclusively, it becomes clear that BYOVD is a permanent threat.

driver

Dell's ' dbutil_2_3.sys ' driver , which is vulnerable to CVE-2021-21551, can facilitate BYOVD attacks, and as Rapid7 researchers warn, this also applies to recent versions.

To exploit the vulnerability, however, malicious actors need administrator privileges, which reduces the chances of exploitation.

However, advanced hackers can use this vulnerability to execute code in kernel mode or hit 0, which is the highest possible privilege level in Windows.

According to Rapid7, malicious actors are still limited to exploiting dbutil_2_3.sys, so versions 2.5 and 2.7 have not yet been abused.

See also: AMD: Fixes dozens of security flaws in Windows 10 graphics driver

However, researchers believe this is only a matter of time, so additional detection and mitigation efforts are needed.

Rapid7 advises administrators to implement the following security measures to prevent malicious driver programs from loading onto their system:

  • Use Microsoft driver exclusion rules (does not currently include Dell drivers)
  • Use the three hashes for 2.3, 2.5, and 2.7 in a third-party EDR solution
  • Enable Hypervisor-Protected Code Integrity (HVCI)
  • Finally, consider submitting the vulnerable drivers to Microsoft to lobby for their inclusion on the exclusion list.
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS