Windows 10: Malware exploits decade old Windows bug, which has an opt-in fix

Discus and support Malware exploits decade old Windows bug, which has an opt-in fix in Windows 10 News to solve the problem; A decade old Windows bug, for which a fix is available, is used by malware currently in attacks against Windows devices. Malware actors may exploit the... Discussion in 'Windows 10 News' started by GHacks, Apr 3, 2023.

  1. GHacks
    GHacks New Member

    Malware exploits decade old Windows bug, which has an opt-in fix


    A decade old Windows bug, for which a fix is available, is used by malware currently in attacks against Windows devices. Malware actors may exploit the vulnerability to add malicious code to signed Windows files without them losing their signed status.

    Digital signatures are used on Windows to determine the authenticity of files. Most security solutions check for signatures when they check files on Windows machines.

    What makes this exploit even more problematic is the fact that a fix is available, but that it is opt-in. If that was not enough, it appears that upgrades to Windows 11 may drop the fix, if applied in the Windows Registry.

    Bleeping Computer reported this week that the VOIP communications company 3CX was compromised. The attackers managed to include malware into the company's desktop application for Windows. Two DLL files used by the desktop application were modified by the threat actors to include malware, more precisely, an information-stealing trojan.

    What makes the attack special is that the attackers are exploiting CVE-2013-3900, WinVerifyTrust Signature Validation Vulnerability, which Microsoft confirmed in 2013 for the first time and has updated in early 2022 with additional information.

    How to protect Windows devices against the attacks


    Malware exploits decade old Windows bug, which has an opt-in fix windows-cert-padding-check.png

    Microsoft published an opt-in fix to address the issue in 2013, and it has been valid ever since.

    Windows 64-bit versions may be protected with the following Registry code:

    Windows Registry Editor Version 5.00
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config]
    "EnableCertPaddingCheck"="1"

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config]
    "EnableCertPaddingCheck"="1"

    Note: you need to paste the code into a plain text file and rename its file extension, so that it is .reg. We have uploaded a Zip archive with Registry files for 32-bit and 64-bit versions of Windows: windows-registry-fix

    All you need to do is double-click on the file to add the information to the Registry (a verification prompt is displayed, which you need to allow).

    A restart of the system is required. Delete the listed Registry values to undo the change at any time.

    Enabling the changes will make non-confirming binaries "appear unsigned" and be rendered untrusted as a consequence.

    Why opt-in?

    Why did Microsoft release the patch this way, and did not integrate it directly into Windows? The extensive FAQ on the support page provides an answer. According to Microsoft, enabling the stricter verification behavior may "impact some installers" and also certain AppLocker behavior and Software Restriction Policies.

    Closing Words

    Windows administrators may check the listed Registry values above to verify if the devices are protected against the vulnerability. Windows devices that were upgraded to Windows 11 need to be rechecked, as the Registry values are likely no longer there after the upgrade. Note that applying the changes using policies should keep them enabled after the upgrade.

    Thank you for being a Ghacks reader. The post Malware exploits decade old Windows bug, which has an opt-in fix appeared first on gHacks Technology News.

    read more...
     
    GHacks, Apr 3, 2023
    #1
  2. PhillipJR Win User

    Autoruns displays decades old timestamps

    Hello,

    I recently reset my Windows 10 installation and it seemed I was attacked by some exploits like trying to rewrite the logon screensaver and writing strange string files to C:\Windows. When checking Autoruns I noticed there were several entries in Task Scheduler
    with timestamps either decades old or decades ahead, some of these are related to Windows Defender. Are these tampered with? or are they normal? They are all verified and 0 on VirusTotal check.
     
    PhillipJR, Apr 3, 2023
    #2
  3. Compumind Win User
    Compumind, Apr 3, 2023
    #3
  4. Malware exploits decade old Windows bug, which has an opt-in fix

    Malware error "Malware Anti-Exploit Protection is not started. The Anti-Exploit process will be terminated" on Windows 10

    Old title: Malware error

    I keep getting the message "Malware Anti-Exploit Protection is not started. The Anti-Exploit process will be terminated." I uninstalled Norton Virus Protection from my computer because it was causing errors. I am using Slim Cleaner as my Anti virus program.
    How do I resolve this error and does Norton Antivirus conflict with Slim Cleaner? Appreciate any assistance given.

    Thanks,
     
    Ms. Jagr55, Apr 3, 2023
    #4
Thema:

Malware exploits decade old Windows bug, which has an opt-in fix

Loading...
  1. Malware exploits decade old Windows bug, which has an opt-in fix - Similar Threads - Malware exploits decade

  2. How do we get Microsoft to fix the decade-old bug in rendering large desktop icons?

    in Windows 10 Customization
    How do we get Microsoft to fix the decade-old bug in rendering large desktop icons?: This bug has been present for more than a decade. Rebuilding the icon cache does nothing. My display drivers are not the issue. Windows simply doesn't know how to handle icons rendered any larger than the default at 1920 x 1080. I guess my question is: how do we make them...
  3. How do we get Microsoft to fix the decade-old bug in rendering large desktop icons?

    in Windows 10 Gaming
    How do we get Microsoft to fix the decade-old bug in rendering large desktop icons?: This bug has been present for more than a decade. Rebuilding the icon cache does nothing. My display drivers are not the issue. Windows simply doesn't know how to handle icons rendered any larger than the default at 1920 x 1080. I guess my question is: how do we make them...
  4. How do we get Microsoft to fix the decade-old bug in rendering large desktop icons?

    in Windows 10 Software and Apps
    How do we get Microsoft to fix the decade-old bug in rendering large desktop icons?: This bug has been present for more than a decade. Rebuilding the icon cache does nothing. My display drivers are not the issue. Windows simply doesn't know how to handle icons rendered any larger than the default at 1920 x 1080. I guess my question is: how do we make them...
  5. Malware or bug??

    in AntiVirus, Firewalls and System Security
    Malware or bug??: there are this apps on my pc running in my taskmanager, there are others too but i succesfully delete them but not these two.when i open their file location i found nothing. several times later i found virus threat setting turned off automaticly.idk about this but everything...
  6. This is a bug or a malware?

    in Windows 10 Ask Insider
    This is a bug or a malware?: when i open the folder it just keeps loading and never stops i used malwarebytes to scan the folder and my whole computer but theres no sign of any viruses and finally i cant do any operations like cut/copy/delete on the folder which have this problem as far i noticed this...
  7. Has the bug for screenshots with HDR has been fixed?

    in Windows 10 Ask Insider
    Has the bug for screenshots with HDR has been fixed?: When I use Snip & Sketch with HDR on under Win10, the screenshots show with all colors messed up. Anyone has found a way to fix this? Thanks! submitted by /u/El_Enemigo [link] [comments]...
  8. Does Malware Anti Exploit work with Microsoft Edge?

    in AntiVirus, Firewalls and System Security
    Does Malware Anti Exploit work with Microsoft Edge?: Title says it all. Malwarebytes web site does not mention Edge? Attachment 103743 I have done research and it seems MBAE may function with Edge. Can somebody confirm either way? 65428
  9. SMB exploitable by malware?

    in Windows 10 Network and Sharing
    SMB exploitable by malware?: I have some backup software that takes backups to a non-mapped NAS share. While a backup is running the cmdlet Get-SmbConnection shows Code: ServerName ShareName UserName Credential Dialect NumOpens ---------- --------- -------- ---------- ------- -------- MYBOOKLIVE...
  10. Decade-old Windows kernel bug lets hackers bypass security protections

    in Windows 10 News
    Decade-old Windows kernel bug lets hackers bypass security protections: Researchers say that a bug in the Windows kernel could allow hackers to perform malicious actions by tricking security products blindly relying on a Windows API. The bug affects a low-level interface, known as PsSetLoadImageNotifyRoutine, that notifies when a module has...