Windows 10: DoubleAgent zero-day hijacks Microsoft tool to turn antivirus into malware

From ZDNet

http://www.zdnet.com/article/windows-10-doubleagent-zero-day-hijacks-microsoft-tool-to-turn-antivirus-into-malware/#ftag=YHFb1d24ec?yptr=yahoo

Came across this in yahoo news. 

6,001 views 8 replies
Reply #1 Top

Ouch! A zero-day attack that targets almost ALL anti virus packages? That's an expensive process to engineer. I wonder if they stumbled onto another Stuxnet class critter.

Reply #2 Top

https://wikileaks.org/ciav7p1/

Reply #3 Top

Quoting benmanns, reply 2

https://wikileaks.org/ciav7p1/


Thought so.

Reply #4 Top

Some sources say that the code had been leaked end of Jan and that it could be found on the DN for staggering price.
This is pretty worrying since it could be potentially an opened pandoras box.

 

Reply #5 Top

Eh? Did you guys watch the video?!

Am I missing something? He uses an ELEVATED cmd window to launch the DoubleAgent executable. Without admin privileges given to it by the user in the first place, DoubleAgent can't do anything. This 'zero-day exploit' is a joke.

Reply #6 Top

I read the article but didn't watch the video. Perhaps I should have.

Reply #7 Top

Quoting JcRabbit, reply 5

Eh? Did you guys watch the video?!

Am I missing something? He uses an ELEVATED cmd window to launch the DoubleAgent executable. Without admin privileges given to it by the user in the first place, DoubleAgent can't do anything. This 'zero-day exploit' is a joke.

the command prompt is launched as admin and might not even be necessary to be launched as such?'
You can run a regsvr without admin rights as far as im aware if you call another action to bypass.
 

 

Reply #8 Top

Not all...there are several AVs which have patched the vulnerability.