
CVE-2022-44721에 대한 익스플로잇으로, Windows에서 CrowdStrike Falcon 제거 보호 토큰 확인을 우회하여 관리자 권한을 가진 공격자가 EDR/AV 센서를 제거할 수 있게 합니다.
CrowdStrike Falcon은 클라우드 기반 엔드포인트 탐지 및 대응(EDR) 및 안티바이러스(AV) 솔루션입니다. 각 엔드 디바이스에는 커널 수준 관리 센서가 배포되어 클라우드 기반 기능을 활용합니다. 센서는 제거 보호 기능으로 구성될 수 있습니다. 이는 일회성 생성 토큰 없이 엔드 디바이스에서 CrowdStrike Falcon 센서의 제거를 방지합니다.
이 취약점을 악용하면 관리자 권한을 가진 공격자가 Windows 엔드 디바이스에서 토큰 검사를 우회하고 적절한 인증 없이 디바이스에서 센서를 제거하여 사실상 디바이스의 EDR 및 AV 보호를 제거할 수 있습니다.
취약한 센서 버전: 6.44.15806
Crowdstrike 지원팀 승인 이메일 발췌
...
As the referenced CVE was not released in coordination with CrowdStrike, it may be missing some details, however our customers
have been kept up to date on our remediation efforts and the affected sensor versions, including a release of the hotfix for v6.44.15806.
Please see the relevant tech alerts explaining the nature of this issue and the fix releases at
https://supportportal.crowdstrike.com/s/article/Tech-Alert-Uninstall-Protection-Bug-in-Falcon-Sensor-for-Windows
Therefore, I believe you can go ahead and publish the CVE adding the impacted Sensor versions
we were able to test and confirm they are affected.
...
이메일에 명시된 바와 같이 Crowdstrike는 이미 취약한 버전을 패치했습니다.
# edit #1
Line 111: std::string cmd = "cmd /c start msiexec /x " + guid;
# edit #2
Line 67: if (g_msiexec_instance_count == 3 || g_msiexec_instance_count == 5) {
.\Falcon-6.44.15806-uninstall.exe "C:\ProgramData\Package Cache\{XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX}v6.44.15806\CsAgent.msi"
테스트 머신 이름: MOANA
정책: EXTRA AGGRESSIVE (모든 옵션 활성화)

제거 진행 중...

제거 완료 (Crowdstrike 디렉터리 내에 더 이상 파일이 없음) - 데몬이 메모리에 여전히 활성화되어 실행 중이면 재시작 필요 (탐지가 생성됨)

Moana 결과를 클라우드를 통해 접근 불가

lsass.exe 덤프

Fortunato [fox] Lodari, Raffaele Nacca, Walter Oberacher, Davide Bianchin, Luca Bernardi @ Deda Cloud 사이버 보안 팀