Wednesday, December 11, 2024
HomeCross site ScriptingHackers Use Windows XSS Flaw To Execute Arbitrary Command In MMC Console

Hackers Use Windows XSS Flaw To Execute Arbitrary Command In MMC Console

Published on

SIEM as a Service

Attackers are leveraging a new infection technique called GrimResource that exploits MSC files.

By crafting malicious MSC files, they can achieve full code execution within the context of mmc.exe (Microsoft Management Console) upon a user click. 

It offers several advantages for attackers by bypassing the need for macros (disabled by default) and providing low-security warnings, making it ideal for gaining initial access while evading detection.

- Advertisement - SIEM as a Service

The first GrimResource sample was uploaded to VirusTotal in early June, highlighting a potentially emerging threat. 

Reference to apds.dll redirect in StringTable

A novel attack technique, GrimResource, exploits an unpatched XSS vulnerability in apds.dll to achieve initial access and code execution on Windows systems, where attackers craft malicious MMC files containing references to the vulnerable APDS resource in the StringTable. 

Scan Your Business Email Inbox to Find Advanced Email Threats - Try AI-Powered Free Threat Scan

Obfuscated VBScript
Obfuscated VBScript

This triggers arbitrary JavaScript execution within the context of mmc.xe, and by abusing DotNetToJScript functionality, attackers further escalate privileges to arbitrary code execution. 

The attack chain uses a transformNode obfuscation technique to circumvent ActiveX security warnings, followed by an obfuscated VBScript that sets the target payload in environment variables. 

A custom.NET loader named PASTALOADER leverages these variables to inject the final payload (e.g., Cobalt Strike) into a newly spawned dllhost.exe process using a combination of DirtyCLR, function unhooking, and indirect syscalls for stealth.  

Payload injected into dllhost.exe
Payload injected into dllhost.exe

An existing detection for suspicious execution via Microsoft Common Console (MSC) files was designed to catch a different technique involving the Console Taskpads attribute. 

It looks for a specific pattern in process creation: a child process spawned by a parent mmc.exe process that launched an MSC file with a wildcard argument but didn’t match known legitimate MMC file locations or whitelisted executables. 

GrimResource detected
GrimResource detected

An attacker can exploit the.NET COM object functionality through a non-standard Windows Script Interpreter (WSH) script engine called DotNetToJScript, which utilizes a trusted process to allocate executable memory (RWX) on behalf of a malicious VBScript or JScript script. 

The detection relies on identifying this abnormal memory allocation pattern along with the call stack involving specific DLLs (mscoree.dll, combase.dll, jscript.dll, vbscript.dll, jscript9.dll, and chakra.dll) that link the.NET process to the WSH script engine. 

Monitoring for suspicious file open events (apds.dll) by mmc.exe can expose attempts to execute scripts through the MMC console. 

apds.dll being invoked in the MSC StringTable
apds.dll being invoked in the MSC StringTable

They can leverage MMC console files (MSC files) to execute malicious scripts by exploiting a vulnerability in APDS (Advanced Protocol Detection Service) to redirect the user to a malicious webpage, which creates a temporary HTML file (redirect.html) in the user’s INetCache folder. 

The Elastic security team can spot this attack by connecting events like the MMC process beginning with an MSC file and creating a redirect.html file.

YARA rules can be used to find the specific features of the malicious MMC console file. 

Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Resecurity introduces Government Security Operations Center (GSOC) at NATO Edge 2024

Resecurity, a global leader in cybersecurity solutions, unveiled its advanced Government Security Operations Center...

Reserachers Uncovered Zloader DNS Tunneling Tactics For Stealthy C2 Communication

Zloader, a sophisticated Trojan, has recently evolved with features that enhance its stealth and...

US Charged Chinese Hackers for Exploiting Thousands of Firewall

The US Treasury Department's Office of Foreign Assets Control (OFAC) has sanctioned Sichuan Silence...

DMD Diamond Launches Open Beta for v4 Blockchain Ahead of 2025 Mainnet

DMD Diamond - one of the oldest blockchain projects in the space has announced the...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

Reserachers Uncovered Zloader DNS Tunneling Tactics For Stealthy C2 Communication

Zloader, a sophisticated Trojan, has recently evolved with features that enhance its stealth and...

US Charged Chinese Hackers for Exploiting Thousands of Firewall

The US Treasury Department's Office of Foreign Assets Control (OFAC) has sanctioned Sichuan Silence...

DMD Diamond Launches Open Beta for v4 Blockchain Ahead of 2025 Mainnet

DMD Diamond - one of the oldest blockchain projects in the space has announced the...