{"id":110103,"date":"2024-08-06T07:00:00","date_gmt":"2024-08-06T14:00:00","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/oldnewthing\/?p=110103"},"modified":"2024-08-06T09:52:18","modified_gmt":"2024-08-06T16:52:18","slug":"20240806-00","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/oldnewthing\/20240806-00\/?p=110103","title":{"rendered":"It rather involved being on the other side of the airtight hatchway: Disabling a security feature as an administrator"},"content":{"rendered":"<p>A security vulnerability report claimed that they were able to bypass a security feature in three easy steps:<\/p>\n<ol>\n<li>Open Regedit.<\/li>\n<li>Go to <tt>HKLM\\<wbr \/>Software\\<wbr \/>Microsoft\\\u27e6redacted\u27e7<\/tt>.<\/li>\n<li>Double-click the <tt>Enabled<\/tt> registry value and change it from 1 to 0.<\/li>\n<\/ol>\n<p>The security feature is now disabled!<\/p>\n<p>Well yeah, because you disabled it.<\/p>\n<p>The <tt>Enabled<\/tt> registry value is in the <tt>HKEY_<wbr \/>LOCAL_<wbr \/>MACHINE<\/tt> portion of the registry which by default requires administrator access to modify. In order to carry out this attack, you have to already be an administrator on the system, in which case a much easier way to bypass the security feature is to just go to the Settings UI for the feature and disable it there.<\/p>\n<p>This is cut-and-dried but it&#8217;s really surprising how often people appear to be concerned that an <i>administrator<\/i> can compromise security.<\/p>\n<p>No really, variations on this non-vulnerability are reported <i>a lot<\/i>. They all boil down to, &#8220;I found a security vulnerability: An administrator can disable a security feature!&#8221; Sometimes, they even admit it themselves: &#8220;You must run the PoC as an administrator.&#8221; Other times, they confess to not being an expert on the subject: &#8220;I am not a security expert, but I can confidently say that I can bypass the security feature using this method.&#8221;<\/p>\n<p><b>Bonus chatter<\/b>: Here&#8217;s another example of a vulnerability report in this category.<\/p>\n<blockquote class=\"q\">\n<p>A malicious driver can bypass or disable Windows security features.<\/p>\n<p>Step 1: Open an elevated command prompt.<\/p>\n<p>\u2026<\/p>\n<\/blockquote>\n<p>Okay, I&#8217;m just going to stop you right there. If your first step is &#8220;open an elevated command prompt&#8221;, then you don&#8217;t need to do all those sneaky things to install the malicious driver in the super-clever way so that it can bypass and disable Windows security features. From the elevated command prompt, you can just disable the security features directly!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>At least they don&#8217;t beat around the bush.<\/p>\n","protected":false},"author":1069,"featured_media":111744,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[26],"class_list":["post-110103","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-oldnewthing","tag-other"],"acf":[],"blog_post_summary":"<p>At least they don&#8217;t beat around the bush.<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/110103","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/users\/1069"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/comments?post=110103"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/110103\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/media\/111744"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/media?parent=110103"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/categories?post=110103"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/tags?post=110103"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}