Just in:
A Bridge Between Deserts and Rainforests: UAE and Costa Rica Forge Economic Ties // Navigating Business Setup in Dubai: A Comprehensive Guide by Czar Bizserv // Abu Dhabi Launches ‘Medeem’ Initiative to Promote Emirati Values in Marriage // A Feast Without Footprint – Shiok Kitchen Catering Redefines Delicious Dining with Carbon Neutral Catering // UAE Delegation Engages in Arab Parliament Committee Discussions // Gunfire exchange near Manipur polling booth // DFA Hong Kong Young Design Talent Award 2024 // Evolution and current state of global crypto adoption – Octa // UN Acknowledges Uneven Progress on Energy Goals During Sustainability Week // NEOM welcomes leading industry figures and investors to Hong Kong showcase as part of its ‘Discover NEOM’ China tour // Keung To Trams Return! “KeungShow HKFanClub” Sponsor Free Tram Rides for All on 30 April to Celebrate Keung To’s 25th Birthday // Petrochemical Storm Clouds Gather Over Saudi Arabia // Hong Kong’s R&D Receives International Recognition HKPC’s “InspecSpider” Wins Prestigious “Edison Award” in Innovation Field // Emirates Offer Support as Wildfires Ravage Greece // Abu Dhabi Environment Agency Endorses ADNOC’s Decarbonization Push // VinFast expands access to comprehensive aftersales network in France and Germany through agreement with Mobivia // AI Race Heats Up: Meta Unveils Powerful New Llama // Takeoff After Turbulence: Flydubai Restarts Operations at Dubai International Airport // Congress Is Set To Perform Well In Lok Sabha Polls In Karnataka // Sharjah Charity International Extends Helping Hand to Flood Victims //

Feature or flaw? How to hijack a Windows account in less than a minute

windows hero

A security researcher has published a way to gain the highest level of a network’s access — without needing a password.

ADVERTISEMENT

Alexander Korznikov said in a blog post that a privileged user, such as a local administrator with system rights and permissions, can use built-in command line tools to hijack the session of another logged-in user who has higher privileges.

He said that if that other logged-in user is a domain administrator, it’s possible to hijack their session, giving that local administrator full access to the network, including domain services.

Using this technique will boot the hijacked user from their session without warning, he said.

Korznikov said that his technique doesn’t always have to be used to gain access to an account with higher privileges — it can also be used by system administrators to gain access to lower accounts, which may not have wider system or network access but works with highly-sensitive company programs or corporate databases.

He explained, (edited for clarity):

“A bank employee has access to a billing system and its credentials to log in. One day, he logs in to the billing system, and starts work. At lunch time, he will lock his workstation. Then the system administrator logs in with his account to the employee’s workstation. According to the bank’s policy, the administrator should not have access to the billing system, but with couple of built-in commands in Windows, the administrator can hijack the employee’s desktop, which is still locked. Now, the administrator can perform malicious actions in the billing system as the employee’s account.”

All it takes is about is about a half-minute of work, according to his proof-of-concept video.

Korznikov called the issue a “high risk vulnerability,” but even by his own admission, he’s not sure if it’s a feature in Windows, or a serious flaw.

Microsoft’s own documentation explains the scope and limitations of the command line tools used in his report, which says the tool should fail when a user fails to enter a password, but Korznikov said he disputes this.

Security researcher Kevin Beaumont confirmed the bug in a tweet, saying it was “very easy” to hijack accounts.

Korznikov said he tested the bug on Windows 7, Windows 10, and Windows Server 2008 and Windows Server 2012 R2, but Beaumont said it works on every supported version of Windows.

But Korznikov hasn’t reported the issue to Microsoft.

“Everything is done with built-in commands,” he says. “Every admin can impersonate any logged in user either locally with physical access or remotely via Remote Desktop,” he said.

“Unfortunately, I don’t know if there some kind of patch and I don’t know what recommendations there could be,” said Korznikov. “Reporting to Microsoft can take six month until [the] issue is resolved, I wanted to notify everyone about that as soon as possible,” he said.

Microsoft did not respond to a request for comment outside business hours.

(via PCMag)

ADVERTISEMENT

ADVERTISEMENT
Just in:
Emirates Offer Support as Wildfires Ravage Greece // Sharjah Charity International Extends Helping Hand to Flood Victims // Navigating Business Setup in Dubai: A Comprehensive Guide by Czar Bizserv // Hong Kong’s R&D Receives International Recognition HKPC’s “InspecSpider” Wins Prestigious “Edison Award” in Innovation Field // Saadiyat Grove Set for Smart Transformation Through Aldar-Siemens Alliance // Takeoff After Turbulence: Flydubai Restarts Operations at Dubai International Airport // VinFast expands access to comprehensive aftersales network in France and Germany through agreement with Mobivia // UN Acknowledges Uneven Progress on Energy Goals During Sustainability Week // NEOM welcomes leading industry figures and investors to Hong Kong showcase as part of its ‘Discover NEOM’ China tour // DFA Hong Kong Young Design Talent Award 2024 // Congress Is Set To Perform Well In Lok Sabha Polls In Karnataka // Petrochemical Storm Clouds Gather Over Saudi Arabia // Abu Dhabi Launches ‘Medeem’ Initiative to Promote Emirati Values in Marriage // Galaxy Macau Unveils the New Galaxy Kidz: An Edutainment Center for Play Time // Andertoons by Mark Anderson for Fri, 19 Apr 2024 // Gen Zs Trust User and Expert Insights on Shopee // AI Race Heats Up: Meta Unveils Powerful New Llama // A Bridge Between Deserts and Rainforests: UAE and Costa Rica Forge Economic Ties // Czar Workspace: a Modern Workspace Solutions in Dubai // Abu Dhabi Environment Agency Endorses ADNOC’s Decarbonization Push //