CIO News Hubb
Advertisement
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact
No Result
View All Result
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact
No Result
View All Result
CIO News Hubb
No Result
View All Result
Home Information Security

Hackers Can Exploit Windows Container Isolation Framework to Bypass Endpoint Security

admin by admin
August 31, 2023
in Information Security


Aug 30, 2023THNMalware / Endpoint Security

New findings show that malicious actors could leverage a sneaky malware detection evasion technique and bypass endpoint security solutions by manipulating the Windows Container Isolation Framework.

The findings were presented by Deep Instinct security researcher Daniel Avinoam at the DEF CON security conference held earlier this month.

Microsoft’s container architecture (and by extension, Windows Sandbox) uses what’s called a dynamically generated image to separate the file system from each container to the host and at the same time avoid duplication of system files.

It’s nothing but an “operating system image that has clean copies of files that can change, but links to files that cannot change that are in the Windows image that already exists on the host,” thereby bringing down the overall size for a full OS.

Cybersecurity

“The result is images that contain ‘ghost files,’ which store no actual data but point to a different volume on the system,” Avinoam said in a report shared with The Hacker News. “It was at this point that the idea struck me — what if we can use this redirection mechanism to obfuscate our file system operations and confuse security products?”

This is where the Windows Container Isolation FS (wcifs.sys) minifilter driver comes into play. The driver’s main purpose is to take care of the file system separation between Windows containers and their host.

In other words, the idea is to have the current process running inside a fabricated container and leverage the minifilter driver to handle I/O requests such that it can create, read, write, and delete files on the file system without alerting security software.

Windows Container Isolation Framework
Source: Microsoft

It’s worth pointing out at this stage that a minifilter attaches to the file system stack indirectly, by registering with the filter manager for the I/O operations that it chooses to filter. Each minifilter is allocated a Microsoft-assigned “integer” altitude value based on filter requirements and load order group.

The wcifs driver has an altitude range of 180000-189999 (specifically 189900), while antivirus filters, including those from third-parties, function at an altitude range of 320000-329999. As a result, various file operations can be performed without getting their callbacks triggered.

Cybersecurity

“Because we can override files using the IO_REPARSE_TAG_WCI_1 reparse tag without the detection of antivirus drivers, their detection algorithm will not receive the whole picture and thus will not trigger,” Avinoam explained.

That having said, pulling off the attack requires administrative permissions to communicate with the wcifs driver and it cannot be used to override files on the host system.

The disclosure comes as the cybersecurity company demonstrated a stealthy technique called NoFilter that abuses the Windows Filtering Platform (WFP) to elevate a user’s privileges to that of SYSTEM and potentially execute malicious code.

The attacks allow the use of WFP to duplicate access tokens for another process, trigger an IPSec connection and leverage the Print Spooler service to insert a SYSTEM token into the table, and make it possible to obtain the token of another user logged into the compromised system for lateral movement.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
Previous Post

161 AWS services achieve HITRUST certification

Next Post

Embracing our broad responsibility for securing digital infrastructure in the European Union

Related Posts

Information Security

New Critical Security Flaws Expose Exim Mail Servers to Remote Attacks

by admin
September 30, 2023
Information Security

Manage AWS Security Hub using CloudFormation

by admin
September 30, 2023
Information Security

Is that how it works? Hacking and scamming in popular TV shows

by admin
September 30, 2023
Information Security

Cisco Warns of Vulnerability in IOS and IOS XE Software After Exploitation Attempts

by admin
September 29, 2023
Information Security

Get the full benefits of IMDSv2 and disable IMDSv1 across your AWS infrastructure

by admin
September 29, 2023
Next Post

Embracing our broad responsibility for securing digital infrastructure in the European Union

Recommended

InnovationBreakthrough Chapter V Innovation Risk Management ~ Future of CIO

September 30, 2023

New Critical Security Flaws Expose Exim Mail Servers to Remote Attacks

September 30, 2023

Manage AWS Security Hub using CloudFormation

September 30, 2023

Is that how it works? Hacking and scamming in popular TV shows

September 30, 2023

InnovationBreakthrough Introduction:Chapter 3 Business Model Innovation ~ Future of CIO

September 29, 2023

Cisco Warns of Vulnerability in IOS and IOS XE Software After Exploitation Attempts

September 29, 2023

© CIO News Hubb All rights reserved.

Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Privacy Policy and Terms & Conditions.

Navigate Site

  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact

Newsletter Sign Up

No Result
View All Result
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact

© 2022 CIO News Hubb All rights reserved.