WEBVTT

1
00:00:03.200 --> 00:00:06.609
This is Decrypted. Monday, the fourteenth of September.

2
00:00:06.609 --> 00:00:11.843
Microsoft's Windows Defender patch didn't survive the week.

3
00:00:11.843 --> 00:00:15.026
A lock changed, not the door.

4
00:00:15.026 --> 00:00:20.139
Microsoft's September Patch Tuesday closed a Windows Defender flaw.

5
00:00:20.139 --> 00:00:23.757
It let a local attacker grab system-level access.

6
00:00:23.757 --> 00:00:31.200
On 9 September, days after that fix shipped, the anonymous researcher who found the original flaw published a

7
00:00:31.200 --> 00:00:33.565
working bypass of Microsoft's own patch.

8
00:00:33.565 --> 00:00:36.626
The new exploit is called ShieldCrash.

9
00:00:36.626 --> 00:00:39.757
It doesn't care that the machine in front of it is fully patched.

10
00:00:39.757 --> 00:00:44.835
This is the latest round in a running fight between one researcher and Microsoft.

11
00:00:44.835 --> 00:00:49.043
And it says more about how software gets fixed than any single vulnerability does.

12
00:00:49.043 --> 00:00:57.078
In August the researcher, who goes by Nightmare Eclipse, also known as Chaotic Eclipse or MSNightmare, publi

13
00:00:57.078 --> 00:00:59.235
shed a proof of concept called ShieldBreak.

14
00:00:59.235 --> 00:01:07.096
It targeted a Defender privilege escalation bug catalogued as C V E twenty twenty-six, six nine four one four

15
00:01:07.096 --> 00:01:09.670
. Microsoft patched it this month.

16
00:01:09.670 --> 00:01:15.837
Within days, Nightmare Eclipse showed that under specific conditions the same underlying problem could still

17
00:01:15.837 --> 00:01:17.843
be triggered. Just through a different route.

18
00:01:17.843 --> 00:01:20.730
Here's what ShieldCrash actually does.

19
00:01:20.730 --> 00:01:26.713
It lets an attacker who already has a foothold on a machine read arbitrary files with system privileges.

20
00:01:26.713 --> 00:01:32.139
That includes the S A M database, enough to pull password hashes for offline cracking.

21
00:01:32.139 --> 00:01:36.313
It's not, by the researcher's own account, a full remote takeover.

22
00:01:36.313 --> 00:01:39.235
There's no arbitrary write and no shell.

23
00:01:39.235 --> 00:01:45.830
But on a "fully patched" Windows 10, 11 or Server box, that's a meaningful hole for anyone who already has a

24
00:01:45.830 --> 00:01:51.026
user-level foothold. And that's most ransomware crews, by the time they start trying to escalate.

25
00:01:51.026 --> 00:01:54.817
Think of ShieldBreak as a badly fitted lock on a restricted door.

26
00:01:54.817 --> 00:01:57.252
Microsoft's patch swapped the lock.

27
00:01:57.252 --> 00:02:00.591
ShieldCrash shows the door frame itself was never fixed.

28
00:02:00.591 --> 00:02:04.765
So a differently shaped bypass gets through, regardless of which lock is fitted.

29
00:02:04.765 --> 00:02:10.470
By the researcher's count, this is at least the ninth Defender-related zero-day dropped since April.

30
00:02:10.470 --> 00:02:16.730
It's part of an increasingly personal dispute with Microsoft over its bug bounty and disclosure practices.

31
00:02:16.730 --> 00:02:20.835
Microsoft hadn't commented publicly on ShieldCrash at the time of writing.

32
00:02:20.835 --> 00:02:27.123
The company has previously warned of legal action against, quote, "malicious activity causing real harm" to c

33
00:02:27.123 --> 00:02:30.435
ustomers, language widely read as aimed at this researcher.

34
00:02:30.435 --> 00:02:33.722
The Secure by Design lesson.

35
00:02:33.722 --> 00:02:37.826
Whatever you make of the researcher's methods, the pattern is the lesson here.

36
00:02:37.826 --> 00:02:43.619
Microsoft keeps patching the specific proof of concept in front of it, rather than the class of bug underneat

37
00:02:43.619 --> 00:02:49.026
h. And it keeps getting bypassed within days, by the same person, probing the same subsystem.

38
00:02:49.026 --> 00:02:54.591
Secure by Design means fixing the design flaw that makes a whole family of bugs possible.

39
00:02:54.591 --> 00:02:57.374
Not shipping a fix narrow enough to route around.

40
00:02:57.374 --> 00:03:00.609
So what should UK organisations take from this?

41
00:03:00.609 --> 00:03:05.235
Two things.

First, "fully patched" is not a security control on its own.

42
00:03:05.235 --> 00:03:10.035
Particularly not for endpoint protection software, which is itself a high-value target.

43
00:03:10.035 --> 00:03:15.670
Second, patch cadence alone won't save you while the vendor is still catching up with its own fixes.

44
00:03:15.670 --> 00:03:22.070
What matters more are defences that assume an attacker already has a foothold: least-privilege accounts, moni

45
00:03:22.070 --> 00:03:26.452
toring for S A M access, and E D R tuned to catch credential dumping.

46
00:03:26.452 --> 00:03:32.035
That was Decrypted. The written version and every source are linked in the show notes.

47
00:03:32.035 --> 00:03:33.287
Thanks for listening.

