Next, Next, SYSTEM: Exploiting NSIS installer bugs to escalate privileges in Zscaler Client Connector
In this blog post I show how patch gaps in Zscaler's bundled NSIS versions led to LPE..
includes PoCs and yara rule to help you find other affected s/w
https://t.co/cFiDsPFDES
"You need to be admin to run the installer anyway."
A common pushback that misses an entire class of attack. New research from @buffaloverflow on exploiting NSIS installer bugs to escalate from a standard user to SYSTEM in Zscaler Client Connector.
NSIS is embedded in thousands of products. Any that launch a vulnerable installer from a privileged service could be affected.
Both CVEs are patched - but silent patching from vendors means most customers never knew they were exposed.
Spin up a NachoVPN server on Azure App Service, reach it via rproxy, supply the hostname over IPC, and the allowlist check passes.
SYSTEM shell in ~30 seconds. No changes to the original exploit chain required. (5/6)
If you recognise any of these sensors from your own building, and they are visible from outside the building - you might want to reach out to us for a chat.
This weekend at @BSidesLondon , Darren McDonald delivered a workshop teaching attendees how to work with our DIY high-powered IR "death lasers" and trigger IR door exit sensors from outside the building!
๐โจ The Saga Continues: MSI Strikes Back โจ๐
TL;DR: Bypass for CVE-2024-12908 - Code execution via Delinea's protocol handler is back. Patch now!
A long time ago (wellโฆ last year), in a protocol handler not so far away, we showed how Delineaโs URL handler could be abused during update (CVE-2024-12908). Weโve now found a new path using msiexecโs PATCH to pull a remote MSP and execute code - even when the MSI is signed!
Netskope has not issued a CVE, noting only in release notes that a โ๐ด๐ฆ๐ค๐ถ๐ณ๐ช๐ต๐บ ๐จ๐ข๐ฑโ was fixed. Full technical details are on our blog: https://t.co/whdQdKrtOT
๐๐ฎ๐ฌ๐ญ ๐๐๐๐๐ฎ๐ฌ๐ ๐ข๐ญ ๐ฌ๐๐ฒ๐ฌ โ๐๐๐๐ฎ๐ซ๐โ ๐๐จ๐๐ฌ ๐ง๐จ๐ญ ๐ฆ๐๐๐ง ๐ข๐ญ ๐ข๐ฌ
Authentication bypasses are not always just about going from unauthenticated to authenticated. What if other customers could gain access to your multi-tenant environment?
We also found all the credential material needed to exploit it available through OSINT, meaning the risk was not necessarily limited to other customers.