Didier Stevens

Thursday 17 November 2011

Hotfix For SRP/AppLocker Bypass

Filed under: Windows 7 — Didier Stevens @ 10:53

Remember Microsoft has features to bypass its own Software Restriction Policies and AppLocker: Circumventing SRP and AppLocker, By Design and Circumventing SRP and AppLocker to Create a New Process, By Design.

Microsoft has issued a hotfix for this bypass: KB2532445

It is only for Windows 7 and Windows Server 2008 R2 though, it will not help you if you use SRP on Windows XP or Vista.

Thanks to @mount_knowledge.

Circumventing SRP and AppLocker, By Design

4 Comments »

  1. Cool. Have you looked at the hotfix to see what the changed behaviour is?

    Comment by olleB — Friday 18 November 2011 @ 13:57

  2. @olleB I’ve tested my PoCs with a beta version of the hotfix, their actions were blocked by SRP/AppLocker.

    Comment by Didier Stevens — Friday 18 November 2011 @ 17:35

  3. Didier,

    Do you know if microsoft solved this issue in Windows 8?

    Kind Regards
    DFT

    Comment by DFT — Wednesday 31 October 2012 @ 11:40

  4. @DFT I don’t think Microsoft considers this an issue, and that it was not included in Windows 8.

    Comment by Didier Stevens — Wednesday 31 October 2012 @ 19:57


RSS feed for comments on this post. TrackBack URI

Leave a Reply (comments are moderated)

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

The Rubric Theme. Blog at WordPress.com.

Follow

Get every new post delivered to your Inbox.

Join 222 other followers

%d bloggers like this: