Or Yair, a security researcher at SafeBreach, recently published a proof-of-concept (POC) showing how anti-malware solutions could be tricked into wiping or permanently deleting harmless files on your PC. The POC is called "Aikido" and is inspired by the Japanese martial art that is used to turn opponents' moves against themselves. And while people continue to debate the usefulness and legitimacy of martial arts, there is no doubt that the Aikido wiper works. That is because Microsoft has already acknowledged the exploit in Defender and has patched the vulnerability.
Other major anti-malware vendors like Avast, AVG, and TrendMicro were also found vulnerable to this flaw. Meanwhile, other popular solutions from the likes of McAfee and BitDefender went unscathed. Here is the full list of the tested products.
Yair explains that the Aikido wiper is based on what is called the time-of-check to time-of-use (TOCTOU) vulnerability. An antivirus solution first detects and determines a file as malicious and then deletes it. Aikido using TOCTOU is used to insert an alternate path after the detection of the malware to then lead to the deletion of a legitimate file instead of that malicious one. Even system files could be deleted using this.
The steps have been described in brief below:
- Create a special path with the malicious file at C:\temp\Windows\System32\drivers\ndis.sys
- Hold its handle and force the EDR or AV to postpone the deletion until after the next reboot
- Delete the C:\temp directory
- Create a junction C:\temp → C:\
- Reboot
Interestingly, in the case of Defender and Defender for Endpoint, Yair noticed that Defender did not delete files, but folders instead. Microsoft has assigned the vulnerability ID "CVE-2022-37971" to this and has patched the issue in the latest Microsoft Malware Protection Engine version 1.1.19700.2.
Meanwhile, TrendMicro, Avast and AVG have also released patches for their own products:
- TrendMicro Apex One: Hotfix 23573 & Patch_b11136
- Avast & AVG Antivirus: 22.10
You can find more details about Akido Wiper and the exploit on SafeBreach's official website here. The Akido Wiper POC was presented at the recent Black Hat Europe 2022 security conference. Hence, you may also find more information on this page.
Via: Dark Reading
12 Comments - Add comment