ADV220005None

Guidance on Microsoft Signed Drivers Being Used Maliciously

Published
December 13, 2022
Last Modified
—

🔗 CVE IDs covered (1)

ADV220005 · pending

📋 Description

Executive Summary: Microsoft was recently informed that drivers certified by Microsoft’s Windows Hardware Developer Program were being used maliciously in post-exploitation activity. Microsoft has completed its investigation and determined that the activity was limited to the abuse of several developer program accounts and that no compromise has been identified. We’ve suspended the partners' seller accounts and implemented blocking detections to help protect customers from this threat. Details: Microsoft was informed that drivers certified by Microsoft’s Windows Hardware Developer Program were being used maliciously in post-exploitation activity. In these attacks, the attacker had already gained administrative privileges on compromised systems prior to use of the drivers. We were notified of this activity by SentinelOne, Mandiant, and Sophos on October 19, 2022, and subsequently performed an investigation into this activity. This investigation revealed that several developer accounts for the Microsoft Partner Center were engaged in submitting malicious drivers to obtain a Microsoft signature. A new attempt at submitting a malicious driver for signing on September 29th, 2022, led to the suspension of the sellers' accounts in early October. Ongoing Microsoft Threat Intelligence Center (MSTIC) analysis indicates the signed malicious drivers were likely used to facilitate post-exploitation intrusion activity such as the deployment of ransomware. Microsoft has released Windows Security Updates (see Security Updates table) revoking the certificate for impacted files and suspended the partners' seller accounts. Additionally, Microsoft has implemented blocking detections (Microsoft Defender 1.377.987.0 and newer) to help protect customers from legitimately signed drivers that have been used maliciously in post-exploit activity. Microsoft is working with Microsoft Active Protections Program (MAPP) partners to help develop further detections and to better protect our shared customers. Microsoft Partner Center is also working on long-term solutions to address these deceptive practices and prevent future customer impacts. Recommended Actions: Microsoft recommends that all customers install the latest Windows updates and ensure their anti-virus and endpoint detection products are up to date with the latest signatures and are enabled to prevent these attacks. Frequently Asked Questions: Are any Microsoft services (Azure, M365, XBOX, Etc.) affected by this issue? Microsoft’s services are not impacted by this issue. Our investigation has not identified any instances of malicious drivers affecting any of our services. How can customers deploy their own Hypervisor-protected Code Integrity (HVCI) policy to perform detections in their own environment? Updates will be made to the Microsoft Recommended Driver Blocklist (Microsoft recommended driver block rules (Windows 10) - Windows security | Microsoft Docs policy to perform detections in their own environment. After the full set of malicious files has been locked, customers (enterprise and consumer) can deploy this policy onto devices to block against this malicious file and other malicious and vulnerable drivers on the blocklist. Additionally, enabling Hypervisor-protected Code Integrity (HVCI) will automatically enforce the policy without needing to deploy the policy.

🎯 Affected products43

  • Windows 10 Version 1607 for 32-bit Systems
  • Windows 10 Version 1607 for x64-based Systems
  • Windows 10 Version 1809 for 32-bit Systems
  • Windows 10 Version 1809 for ARM64-based Systems
  • Windows 10 Version 1809 for x64-based Systems
  • Windows 10 Version 20H2 for 32-bit Systems
  • Windows 10 Version 20H2 for ARM64-based Systems
  • Windows 10 Version 21H1 for 32-bit Systems
  • Windows 10 Version 21H1 for ARM64-based Systems
  • Windows 10 Version 21H1 for x64-based Systems
  • Windows 10 Version 21H2 for 32-bit Systems
  • Windows 10 Version 21H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for x64-based Systems
  • Windows 10 Version 22H2 for 32-bit Systems
  • Windows 10 Version 22H2 for ARM64-based Systems
  • Windows 10 Version 22H2 for x64-based Systems
  • Windows 10 for 32-bit Systems
  • Windows 10 for x64-based Systems
  • Windows 11 Version 22H2 for ARM64-based Systems
  • Windows 11 Version 22H2 for x64-based Systems
  • Windows 11 version 21H2 for ARM64-based Systems
  • Windows 11 version 21H2 for x64-based Systems
  • Windows 7 for 32-bit Systems Service Pack 1
  • Windows 7 for x64-based Systems Service Pack 1
  • Windows 8.1 for 32-bit systems
  • Windows 8.1 for x64-based systems
  • Windows RT 8.1
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
  • Windows Server 2008 for 32-bit Systems Service Pack 2
  • +13 more not shown

✅ Remediation

KB5022286 (Security Update) — fixed build 10.0.17763.3887 KB5022282 (Security Update) — fixed build 10.0.19043.2486 KB5022291 (Security Update) — fixed build 10.0.20348.1487 KB5022282 (Security Update) — fixed build 10.0.19042.2486 KB5022287 (Security Update) — fixed build 10.0.22000.1455 KB5022282 (Security Update) — fixed build 10.0.19044.2486 KB5022303 (Security Update) — fixed build 10.0.22621.1105 KB5022282 (Security Update) — fixed build 10.0.19045.2486 KB5022297 (Security Update) — fixed build 10.0.10240.19685 KB5022289 (Security Update) — fixed build 10.0.14393.5648 KB5022338 (Monthly Rollup) — fixed build 6.1.7601.26321 KB5022339 (Security Only) — fixed build 6.1.7601.26321 KB5022352 (Monthly Rollup) — fixed build 6.3.9600.20778 KB5022346 (Security Only) — fixed build 6.3.9600.20778 KB5022340 (Monthly Rollup) — fixed build 6.0.6003.21872 KB5022353 (Security Only) — fixed build 6.0.6003.21872 KB5022348 (Monthly Rollup) — fixed build 6.2.9200.24075 KB5022343 (Security Only) — fixed build 6.2.9200.24075

🔗 References (30)