Windows Smart App Control Flaw Exploited Since 2018, Experts Warn

05 Aug 2024

Design Flaw in Windows Security Features Exploited Since 2018

A significant design flaw has been identified in Windows Smart App Control and SmartScreen, allowing attackers to execute programs without triggering the expected security warnings. This vulnerability has reportedly been exploited since at least 2018, raising concerns about the effectiveness of these security measures.

Smart App Control serves as a reputation-based security feature, leveraging Microsoft’s app intelligence services to predict safety and utilizing Windows’ code integrity features to identify and block untrusted or potentially harmful applications. This feature is a successor to SmartScreen, which was first introduced in Windows 8 to guard against malicious content. Both systems activate when users attempt to open files marked with a Mark of the Web (MotW) label.

Elastic Security Labs Uncovers LNK Stomping Technique

Recent findings from Elastic Security Labs have shed light on a specific bug related to the handling of LNK files, a technique referred to as “LNK stomping.” This method allows threat actors to circumvent the security controls of Smart App Control, which are intended to prevent the execution of untrusted applications. LNK stomping involves the creation of LNK files with unconventional target paths or internal structures. When a user interacts with such a file, the Windows Explorer modifies it to conform to the correct canonical format, inadvertently stripping away the MotW label that triggers security checks.

To exploit this vulnerability, attackers can manipulate the target executable path by appending a dot or space (for example, “powershell.exe.”) or by crafting an LNK file with a relative path like “.target.exe.” Upon clicking the link, Windows Explorer identifies the corresponding .exe file, updates the path, removes the MotW label, and proceeds to launch the executable.

Elastic Security Labs has observed multiple instances of this exploit in the wild, with samples dating back over six years, indicating a long-standing issue. The lab has communicated these findings to the Microsoft Security Response Center, which has acknowledged the problem and indicated that a resolution may be included in a future Windows update.

Additional Vulnerabilities Highlighted

In addition to LNK stomping, Elastic Security Labs has highlighted several other vulnerabilities that could be leveraged to bypass Smart App Control and SmartScreen:

  • Signed malware: Utilizing code-signing or Extended Validation (EV) signing certificates to sign malicious payloads.
  • Reputation hijacking: Repurposing applications with established good reputations to evade detection.
  • Reputation seeding: Deploying binaries controlled by attackers onto systems, which may contain known vulnerabilities or malicious code that activates under specific conditions.
  • Reputation tampering: Injecting harmful code into binaries while maintaining their associated reputation.

Elastic Security Labs has issued a warning regarding the fundamental design weaknesses in Smart App Control and SmartScreen, emphasizing that these flaws can facilitate initial access without security warnings and with minimal user interaction. They advise security teams to conduct thorough scrutiny of downloads within their detection frameworks and not to rely solely on native operating system security features for protection.

In an effort to assist defenders in identifying these activities until a patch is released, Elastic Security Labs has shared detection logic and countermeasures. Additionally, researcher Joe Desimone has made available an open-source tool designed to assess a file’s trust level within Smart App Control.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
4942579
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
826121
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
418145
downloads
Geometry Dash

Geometry Dash

Latest update Geometry Dash download for free for Windows PC or Android mobile

4
539 reviews
304379
downloads

News and reviews for Desktop Windows

Microsoft's Potential Handheld Gaming Plans Spark Interest

Speculation grows over a Microsoft device as a potential handheld competitor to the Steam Deck, potentially unveiled at the Xbox Games Showcase.

Read more

Hellslave RPG Available Free on Steam For Limited Time

The dark fantasy RPG Hellslave is now free on Steam, as its sequel approaches. Experience this dungeon-crawler and retain it in your library forever. Claim it by June 16.

Read more

Foxtail Unveils Hidden Gem from Comiket 81 in Gaming History

A mysterious disc titled Action RPG (Temp) C81 Demo Version reveals a rarely seen game from Comiket 81 in 2011, featuring unique stamina-based combat. The demo offers a glimpse into a creative era of RPGs, thanks to the dedicated work of developer Foxtail.

Read more

IO Interactive Unveils New James Bond Game: First Light

IO Interactive announces 007 First Light, a new video game featuring an original James Bond origin story. Players will earn their 00 status in this immersive gaming experience crafted for a fresh perspective within the Bond series.

Read more

Anvil Empires Aims to Revolutionize Medieval RTS Gaming

Anvil Empires, a medieval RTS game inspired by Age of Empires 2, offers a large-scale playtest. It combines classic strategy mechanics with MMO elements, allowing up to 1,000 players per server. The focus is on logistics and teamwork.

Read more

Atomic Heart Game Offers Up to 71% Off Sale This Year

Atomic Heart, a distinctive shooter set in a robot-dystopia, is on sale with a 71% discount. Experience the narrative of rebellion against an authoritarian regime as P-3. With elemental powers and melee combat, it promises a unique adventure at $21.09 / £15.49.

Read more

IO Interactive Reveals James Bond Game 007 First Light

IO Interactive announces 007 First Light, a new James Bond game. The long-awaited origin story adds to the Bond franchise's gaming legacy. Fans eagerly await the full reveal, marking IO Interactive's first major step since 2020.

Read more

Nightreign Patch Improves Gameplay for Singleplayer Mode

The Nightreign patch adds auto-resurrect and boosts levelling, addressing challenges in singleplayer mode. Players now experience improved balance and performance, aligning with FromSoftware's commitment to refining gameplay.

Read more

Elden Ring Patch Enhances Solo Gameplay Dynamics

Elden Ring receives a solo gameplay boost with the Nightreign patch. The update introduces automatic revival and improved rewards, enhancing gamers' experiences.

Read more

Medal of Honor Game Reimagined with Unreal Engine 5

The classic Medal of Honor Allied Assault is reimagined using Unreal Engine 5, receiving praise from original game designer Nathan Silvers. The remake highlights the enduring legacy of the game, despite the uncertain future of the Medal series.

Read more