Windows SmartScreen and SAC Vulnerabilities Exposed by Researchers

06 Aug 2024

Windows Smart App Control and SmartScreen

When activated, SAC supersedes and disables Defender SmartScreen, while Microsoft has made available undocumented APIs that allow for the assessment of a file's trust level within both SmartScreen and SAC. This accessibility has empowered researchers to create tools that can evaluate the trustworthiness of files more effectively.

Researchers from Elastic Labs have delved into reputation-based and LNK (shortcut) file techniques to exploit these systems, aiming to gain unauthorized access to devices.

Exploiting Reputation Systems to Bypass SmartScreen

One notable method for bypassing SAC involves the use of legitimate code-signing certificates to sign malware. Attackers have increasingly acquired Extended Validation certificates, which necessitate identity verification, by impersonating legitimate businesses. A case in point is the SolarMarker threat group, which has leveraged over 100 distinct signing certificates in its operations.

Another approach, termed reputation hijacking, repurposes trusted applications to evade security protocols. Script hosts with foreign function interfaces, such as Lua and Node.js interpreters, are particularly susceptible to this tactic. By utilizing these trusted applications, attackers can load and execute malicious code without raising any alarms.

Detecting reputation hijacking can be challenging, given the multitude of applications that can be exploited for this purpose. However, security teams can devise behavioral signatures to identify general categories of compromised software. For instance, they may monitor for common Lua or Node.js function names or modules within suspicious call stacks, or leverage local reputation systems to pinpoint anomalies that require further scrutiny.

LNK File Vulnerability and Detection Strategies

A significant vulnerability has been uncovered in Windows' handling of LNK (shortcut) files. By crafting LNK files with unconventional target paths, attackers can bypass Mark of the Web (MotW) checks, effectively evading the protections offered by SmartScreen and SAC. This flaw, which has persisted for at least six years, permits arbitrary code execution without triggering security warnings.

To mitigate these risks, security teams should adopt multi-layered detection strategies. This includes cataloging and blocking known abused applications, developing behavioral signatures to recognize suspicious activities, and maintaining vigilant monitoring of downloaded files. For example, teams can establish rules to detect common function names or modules associated with compromised script hosts in call stacks. Additionally, a focus on local reputation systems can aid in identifying outliers within the environment that merit closer examination.

It is essential for security teams to conduct thorough scrutiny of downloads within their detection frameworks, rather than relying exclusively on OS-native security features for safeguarding against these vulnerabilities. The researchers emphasize that in-memory evasion, persistence, credential access, enumeration, and lateral movement behaviors can be instrumental in identifying reputation hijacking techniques in practical scenarios.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6237224
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1209578
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
470235
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
451108
downloads

News and reviews for Desktop Windows

Just Dance 2026 Launches with New Features for PC and Consoles

Released on 2025-10-25, Just Dance 2026 offers new music, a camera controller, and Party Mode.

Read more

Wordle's Latest Update Reveals 'Plump' as Today's Answer

Wordle's answer for 2023-10-26 is 'Plump,' a five-letter word. Check hints and strategy tips for better gameplay.

Read more

Paradox Expands DLC Model to Sustain Game Lifespan

Paradox's DLC model supports game longevity, says Johan Andersson. The strategy adds new features and responds to player feedback.

Read more

Satisfactory 1.2 Enhances Fluid Transport with New Features

Coffee Stain Studios' Satisfactory 1.2 to introduce tanker trucks for fluid transport, boosting player options and performance.

Read more

Warhammer Day Unveils Game Updates and Future Releases

Warhammer Day introduces updates and reveals across titles like Boltgun 2 and Darktide, impacting 2025 and beyond.

Read more

EFT Arena Free Weekend Launches with Season 1

Battlestate Games offers EFT Arena free this weekend, boosting gameplay interest. Discounts on Epic Games Store expected to drive sales.

Read more

TWW3 Hotfix to Address AI and Recruitment Issues by Early November

Creative Assembly plans hotfix 6.3.4 for TWW3, aiming to fix AI and recruitment issues by early November. Impact expected on Chaos Dwarfs and Ogre Kingdom.

Read more

Halo: Unreal Engine 5 Remake Set for 2026 Launch

Halo Studios announces 2026 release of Halo: Campaign Evolved for PC Xbox App and Game Pass, enhancing original Halo with UE5 and new features.

Read more

Top Antivirus Software for 2025 Ensures Multi-Device Security

Explore the best antivirus solutions for 2025 to secure both computers and mobile devices. Protect against cyber threats with comprehensive cross-device coverage.

Read more

Microsoft Patches Critical WSUS Vulnerability in Windows Server

Microsoft addresses critical WSUS vulnerability in Windows Server. Patches issued as exploitation activity rises.

Read more