this post was submitted on 22 Jun 2023
12 points (100.0% liked)

Cybersecurity

5739 readers
17 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 1 year ago
MODERATORS
 

I only know about CVE-2013-3900 (WinVerifyTrust) which allows modified files to pass signature check unless you tweak registry to enable patches.

I think there must be other instances like this where Microsoft won’t fix vulnerability or chooses insecure defaults, is there a list?

top 6 comments
sorted by: hot top controversial new old
[–] [email protected] 9 points 1 year ago

Of course, tons of tax dollars are spent hoarding vulns

https://en.wikipedia.org/wiki/Vault_7

[–] [email protected] 7 points 1 year ago

There are literally hundreds to thousands. Many of them are horded by governments, APTs, and pen testers. I personally abused a 10 year old CVE for pen tests that was known to be used by non US government entities for a zero click code execution on opening a word doc.

Then there are things that are vulnerabilities but cannot be fixed as they are intensic to how Windows functions. Some can be hardened from the defaults but break compatibility and some cannot be fixed without a complete rewrite of how Windows and AD work. Disa stigs will give you defaults that can be hardened. Requirements for all domain users to see all GPOs, users, groups in order for AD to work is an example of something that cannot be fixed without a complete rewrite. That means an in privileged user can get a list of all users, all domain administrator, names of all computers on the domain, etc. As an attacker, that is invaluable.

Short answer, that list is to big and changes constantly. None that would be comprehensive, but disa stigs is a good place to start.

[–] emergencycall 5 points 1 year ago

Highly depends on your definitions of the words "vulnerabilities," "Windows," and "patched." By Microsoft's definitions of these words, the answer would be no.

[–] [email protected] 3 points 1 year ago* (last edited 1 year ago)

Don't know precisely, but hear from time to time that Microsoft is notorious for not patching in time in many cases, leaving vulnerabilities for months and sometimes years. I am pretty sure that MS just kinda gave up on the vulnerabilities MimiKatz exploits, so if the bad guys are on your network and you use MS infra it's pretty much a question of time before they get admin credentials.

[–] [email protected] 2 points 1 year ago

how much $$ ya got. :P

[–] tcely 1 points 1 year ago

A fair number of vulnerabilities exist where a patch or mitigation exists, but hasn't been widely applied for various reasons.

load more comments
view more: next ›