Bitdefender's challenge.
Comments
-
@camarie, @Alexandru_BD can you check on this and share with the developers.
Regards
Life happens, Coffee helps!
Show your Attitude, when you reach that Altitude!
Bitdefender Ultimate Security Plus (user)
1 -
Done. It is not clear at this time what the payload does.
1 -
I could help, if I can get in contact with someone in charge. The attack method should not be published yet, so here is my email:
(email address removed by admin)
Regards
0 -
Thanks, notified the guys here.
Anyways, since the proof of concept requires Admin rights, it's not really an exploit IMHO - one can simply uninstall the product for example.
But as soon as I know more I will get back.2 -
I am not sure if this method can be called an exploit. Anyway, it can tamper with kernel drivers and protected services so one could call it an exploit of antimalware self-protection.
I think that it can be (or already is) used in remote attacks or lateral movement against organizations. I noticed that one could use it to tamper with one or two drivers to invalidate some features like behavior shield, anti-ransomware shield, sandbox, etc. Here is an example of Avast:
One could easily use this method in the widespread attacks via ISO or IMG disk image files, because most users ignore UAC prompts. The attack can be masqueraded as an update to be more convincing. But currently, there are several more popular methods, so I think that it is rather adjusted to be a part of targeted attacks on organizations.
0