Transcript
We've made it to the seventh month of the year already. And we're here on this wonderful Tuesday to talk about some amazing fixes Microsoft has released in their products on this Patch Tuesday. I'm Tom, thanks for joining. It's been a very long time since I've been on this podcast, but I'm happy to be filling in for Ryan while he's on vacation, making the rest of us jealous. So, yeah, definitely an interesting Patch Tuesday. We got some good things to talk about here in these release notes. And the first one that we kind of ran through internally, is more BitLocker bypasses. And specifically for this one, CVE-2025-48001, which is kind of a race condition in BitLocker that allows kind of a physical attack on devices, which I thought was really, really, really interesting. But, you know, I'm curious, Seth, what are your thoughts on this one specifically? Yeah, so like you said, this one is a physical attack. You actually have to have the device in front of you. And so for this one, basically, what's broken here is BitLocker is, it's like a pre-boot process. So the system checks the protection state. So that would be like what the TPM folds. And then it'll check like the boot drives, things like that. And then after that check happens, it releases that to, it actually releases it to RAM, and then it can then decrypt the drive. So what's happening here is a time of check and a time of use race condition. So again, as I was saying, like, so the BitLocker boot environment will verify the TPM values, the secure boot state and the required filter drives. And then after that check happens is the time of use. So immediately after that, it unseals the full volume encryption key, and then it places it in memory for it to use. So what happens here is the vulnerability will arise because the attacker with direct access to that hardware. So, you know, again, this is going to affect lost or stolen laptops. And this primarily affects, well, it's anybody that uses BitLocker. But, you know, a lot of corporations are using BitLocker and are relying on that to keep their device secure in the event it gets lost or stolen. So that's how this attack works. So basically, what would happen is, you know, you have an adversary that would steal a laptop and have physical control of that. And, you know, it's a pirate powered offer in Hibernate. They would attach what's called a DMA capable device or swap the drives registry or filter drive configuration during the bootloader. So that's kind of how it works. And then from there, they bypass encryption, they have access to that key. So from there, they can do anything. They can data exfil, they can try PrivEsc. There's a ton of different things they can do. I mean, they have full access to the hard drive at that point, completely unencrypted. So to kind of mitigate that, you can do other things in the BIOS. You can do like a pre-boot pin, where before all of those checks even happen, you have to put in a pin or a password. You know, you can tighten up physical security. And then, of course, patching will hopefully fix this. So yeah, that's basically it on that one. Yeah, it's absolutely crazy to me how low this is rated, right? Because you make such a great point about lost or stolen laptops, because often those things don't get wiped, right? Because they never connect to the internet again. They're just kind of stolen. And then placed somewhere in a wheelhouse and overseas to another country to be kind of stored until vulnerabilities like this happen. And then they can kind of bypass BitLocker with a physical device at hand and then do what they may with the device after the contents of the hard drive are decrypted, right? So to me, this feels like one of those like, yeah, it's low and they're kind of downplaying. Well, the attack vector, you got to have physical access to the device. But no one really cares about stolen devices these days. No one's really retrieving them. They're mostly just writing it off and then buying the employee a new device, right? And completely relying on built-in features within Mac or within Windows to protect the confidentiality of these drives. So it's crazy how low this is rated, given, I think, the implications for everyone involved. So yeah, really, really interesting. Speaking of booting, secure boot certificates expire June of next year, which is quite the interesting timing and a little bit of Microsoft giving us a one-year heads up, which I think is probably not enough time, given how this industry works. And I'm real curious, Cody, what your take on this one is specifically. Yeah, it's going to be interesting. So basically, everything that's not a Copilot Plus PC released this year, I think as of April this year, is going to be affected by this. So you will have to go. And so there's two routes to this. One is that you are an enterprise customer, and you have to be opted into updates. Otherwise, you will not get the update for some reason. The second route is for everybody who's not enterprise, and you have to kind of follow the same little workflow logic of you have to go edit your registry keys, and you have to set a specific key to a weird D value or D word value, which is like 5944, which gets you opted into the auto patch service. The other concern with all of this is so these are all expiring, and it seems like the only way that they're willing to update devices is if you are also sending diagnostic data. So if you're worried about sending, like telemetry back to Microsoft, it gets even harder to try to update your secure boot stuff. But I don't know, I guess the risk is quite large, though, because you won't be able to install secure boot updates, you won't be able to trust third party software after June of next year for most in October for a couple of them. Yeah. And then you won't be able to update your boot manager after October. So it's quite the litany of problems if you cannot get this solved. Luckily, they are making it somewhat easy to do. And they do have a page that you can go, you can go download their app, and it'll let you know if you're already opted in or if everything's set up correctly. So it'll do the registry key checks and everything for you. And I believe they've already started rolling out updates as of last month. And they are still going to release secure boot updates for Windows 10 after October 2025, because I believe October of this year is when they stop support entirely for Windows 10. But they have committed to updating everything for that as well. Yeah, the other thing with that secure boot, that's kind of like your first line of defense against boot kits, too. So after that certificate expires, like that leaves anything that's not updated at risk. Oh, yeah. And another one to think of, too, is if you currently have secure boot disabled, you will also not be able to get the updated certificates. So they're recommending that you turn secure boot on to get the updates. And then if you want it off, to turn it back off. So it's kind of a mess. And yeah, I agree. One year in enterprise stuff is just not long enough. So I think we're going to see a lot of physical devices just have secure boot issues. And we're probably going to see a lot of people just unable to use third party software in about a year. Yeah. I mean, outside of the enterprise, right? I just Windows is still king everywhere. And yeah, I just can't imagine like walking your grandma through this nasty problem, right? Like it just there's got to be an easier way here. And I appreciate all the guidance Microsoft provided in their article and those kind of things. But these are the things I think about is like, okay, cool. Well, most devices in the enterprise are MDM and we could push down like a group policy or something, or you could write an automax worklet or whatever to manage this kind of registry value. But, you know, if your grandma, that computer that your kids use or whatever, you know, do they even know? Do they even care? Are there going to is there going to be pop ups, right? That could walk somebody through it on devices that are not enterprise managed. If you see pop ups, don't click them. Never click a pop up. That's so true. It's so true. You know, look, Tom, it's 2025. If your grandmother doesn't know how to edit the registry yet. It's true. Maybe Copilot can do that for us. We can just ask, can you update this registry value? So I'm ready for a secure boot, you know, missed opportunity by Microsoft. You know, if you're asking me right here, Copilot use, boom, done, right? Let them know. Absolutely. Cool. Yeah. So just to summarize all the Microsoft ones that we found interesting, obviously BitLocker, right? Make sure you're keeping that up and keep an eye out on these expiring certificates in secure boot as that rolls out before it expires in June of next year. Couple other things that really piqued our interest this these past couple of weeks, right? Is CVE 2025-32463, which is another true vulnerability. And yeah, it's just it feels like another one of those Linux things where, right, the hardest, the easy part is getting on the host, right? And when you're a low priv user in Linux, a lot of times you can't really do much, right? People do in the modern world usually do a pretty good job of like, you know, only running things as low priv users or applications like Nginx or Apache do a good job of, you know, reducing capabilities down to like a user level instead of running as root. But, you know, getting on a getting on a box and finding, you know, an outdated root or an outdated sudo is a really, really, I think, easy find these days, and especially in, you know, outside of the enterprise and like CTF land freight, all these things, all of these things always remind me of that, right? Like a hack the box type machine where you got to exploit this single vulnerability. But, you know, I'm curious to your thoughts on this one, Cody, as well. Yeah, so this one's this one's interesting because the vulnerability is in between where it starts to pivot the root and unpivot the root in the true binary. So for one, you should never rely on true as a security mechanism. It has so many problems that, you know, it's been exploited many times over. But it is a good part of the you know, the security onion, I guess. So, but in between, in between the parts where it starts to pivot the root ID of the virtual changer, it makes a call out to NS switch. So one of the big problems is that you can shoot into a directory and you can overwrite the NS switch and that allows you to load shared libraries. So you can do like completely complete shared objects. And I think the the demo that they have for like the POC that they have involves just calling a password at the password. So it's able to dump the entirety of password into the rooted binary environment. But it's pretty trivial to make it do anything else. If you I'm sure will link the article to it near the bottom of the article, you can see the call chain. And inside there, you can just chain out to as many DLLs as you want, it looks like. And then kind of circumvents the PAM approval as well, which was another interesting one that I saw. And, yeah, I mean, being able to do this is very trivial. It's like 20 lines of code or less, I think. It ends up being, well, actually, the POC itself is eight lines or nine lines of code. So, yeah, in nine lines, you've got root. Amazing, right? Just amazing. And these things too, you know, sometimes these things can lead to like container breakouts or other similar, you know, attack vectors when you're operating in like a containerized environment as so many enterprises use today. And, you know, a lot of the industry doesn't necessarily think about these kind of deep kernel exploits, right, of containers and Kubernetes and all these things because they're, well, it's in a container, it's fine, right? But the reality is, it's like everything is shared underneath, right, in a lot of senses. So, like NS switch and all those commands still apply in a containerized environment. So, just because you're running a container doesn't necessarily mean you're safe from this. So, you know, keep an eye out for a lot of those things. But yeah, just another, all these tools that we just trust, right? Well, you know, Sudo and Trude and all these kind of security. It's funny because we've talked only about security kind of controls, right, in this podcast so far. BitLocker and Secure Boot and all these tools are often just as exploited as, you know, Word or other type tools, right? So, it's the attack services always there ever growing in the industry. Speaking of attack surface, right, the one final thing we wanted to talk about today was this zip trick, which unfortunately, you know, to me feels really just weird, right? Like all these zip tricks and all these polymorphic attacks that you see sometimes, you know, these texts and JPEGs and those sort of things are always interesting, right? How you can abuse a trusted system like a zip file or other similar things and, you know, bypass security measures or exploit systems or do those kind of things. You know, sometimes it's a little researchy when you're reading through these exploit chains. But I do think that, you know, something like this one is probably a little less researchy and a little more practical in the day-to-day. And I'm curious to y'all's thoughts on that one. Yeah, this one's interesting. They take the approach of not polymorphic, but schizophrenic zip, that's what they're calling it. So, yeah, so the way that I'm understanding it is you're basically modifying part of like the end of central directory record at the top. And you're hiding files at the beginning of central directory, but you're modifying the offset. So you're only showing a specific subset of files. And I guess one of the ways or one of the technical demonstrations they did were with invoices. So they're showing you one invoice and like this PDF inside the zip. And you go to pay the invoice, I guess. And it's sending off a separate PDF file to a different company with all of your bank account information. So, yeah, lots of weird stuff to this one. But it seems very, I mean, it's very trivial. It's another trivial one. You know, you're just modifying the header or the zip header. And that's it. Like with this one, when you and then like, because you would just create a directory with both benign and malicious files. Like that's pretty basic. Yeah, absolutely. The other big one too is a lot of the hidden files can be executed without, you know, you ever even seeing them. So while it's being skipped in like the view state. So if you go to look at the zip, like the zip directory, you don't see the files in there. But as you're unzipping it, it can execute stuff inside that hidden area of the central directory. Yeah, who's going to look at, you know, what's unzipping versus what they previewed, right? Like, it's just one of those areas in the modern workforce. We just blindly trust, right? Like a zip file. No one knows that it can be used for like these kind of abuse mechanisms. So yeah, just a great place to kind of attack, you know, attack a company, whether you're doing it for a malicious intent, or maybe like an academic type of red team exercise, like this article shows specifically. It's just, you know, everything can be abused and all of these trusted systems we have in the modern workforce is right for exploitation, right? And that's the unfortunate reality of security. You know, you always got to be paranoid about everything. Yeah. Oh, cool. Oh, the other interesting part of it was, I guess one of the things they noticed is that it will detect the software stack that you're on and change the visibility in the central directory based on that. So like they're talking about attempting to target somebody who approves invoices, so they'll approve the correct one. So it looks correct, because obviously they're going to be able to validate it. But when your finance team goes to pay it, you know, your finance team has no idea about your IT stack, right? So it's detecting that they're running like payment software or whatever, QuickBooks 2003, who knows? And that's when it'll change the visibility of the file. So I thought that was interesting, too. Nice. Yeah, absolutely. And that's where the schizophrenic part comes in. I mean, it's true to name, true to name for sure. Cool. Well, that's kind of all we had today. We appreciate your continued support as we ramble on about Microsoft's latest release notes and some other interesting things we find layering around the web. Happy July, everybody. And thank you all for tuning in to this episode of Fix Tuesday.