Chinese Hackers Stole an NSA Windows Exploit in 2014
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-0005 | Local Privilege Escalation Flaw in Microsoft Windows GDI CVE-2017-0005 is an elevation of privilege vulnerability in the Graphics Device Interface (GDI) component of Microsoft Windows, scored 7.8 (High) because a successful exploit compromises confidentiality, integrity, and availability. It is triggered when a local, low-privileged user runs a crafted application that manipulates GDI, causing code to run with elevated privileges. An attacker who already has a foothold on a machine (e.g., via malware or a compromised account) gains higher privileges, enabling full control of the host, persistence, and access to sensitive data. The flaw affects a broad set of Windows releases from Windows Vista SP2 through Windows 10 1607, plus Windows RT 8.1 and Windows Server 2008, 2012, and 2016, so most Windows estates of that era are in scope. Exploitation is confirmed in the wild: Microsoft published detection and mitigation guidance for an actively used exploit in 2017, and CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2022-05-24; EPSS estimates a ~10.9% probability of exploitation within 30 days (96th percentile). Do: Apply Microsoft's security updates for all affected releases per the CISA KEV required action: Windows 10 1507/1511/1607 via cumulative updates, and Windows 7 SP1, 8.1, RT 8.1, Server 2008 SP2/R2 SP1, Server 2012 Gold/R2, and Server 2016 via the corresponding vendor patches. Out-of-support versions such as Vista SP2 or Server 2008 need extended/custom-support updates or an OS upgrade, and Windows 10 devices on 1507/1511/1607 should be moved to a currently serviced build. Because exploitation requires local code execution, restrict untrusted local software, and review Microsoft's MMPC detection guidance referenced for this CVE to hunt for prior exploitation. | 7.8 | 11% | KEV PoC |
| masshundreds of millions of Windows PCs and servers across the affected Vista through Windows 10 1607 / Server 2008-2016 releases |
Full article221 words · extracted from schneier.com · click to collapse
Check Point has evidence that (probably government affiliated) Chinese hackers stole and cloned an NSA Windows hacking tool years before (probably government affiliated) Russian hackers stole and then published the same tool. Here’s the timeline:
The timeline basically seems to be, according to Check Point:
- 2013: NSA’s Equation Group developed a set of exploits including one called EpMe that elevates one’s privileges on a vulnerable Windows system to system-administrator level, granting full control. This allows someone with a foothold on a machine to commandeer the whole box.
- 2014-2015: China’s hacking team code-named APT31, aka Zirconium, developed Jian by, one way or another, cloning EpMe.
- Early 2017: The Equation Group’s tools were teased and then leaked online by a team calling itself the Shadow Brokers. Around that time, Microsoft cancelled its February Patch Tuesday, identified the vulnerability exploited by EpMe (CVE-2017-0005), and fixed it in a bumper March update. Interestingly enough, Lockheed Martin was credited as alerting Microsoft to the flaw, suggesting it was perhaps used against an American target.
- Mid 2017: Microsoft quietly fixed the vulnerability exploited by the leaked EpMo exploit.
Lots of news articles about this.
Sidebar photo of Bruce Schneier by Joe MacInnis.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2021/03/chinese-hackers-stole-an-nsa-windows-exploit-in-2014.html