Bundled version of Node.js simplifies executing downloaded code
Adobe Creative Cloud Experience, a service installed via the Creative Cloud installer for Windows, includes a Node.js executable that can be abused to infect and compromise a victim's PC.
Michael Taggart, a security researcher, recently demonstrated that the node.exe instance accompanying Adobe's service could be exploited by writing a simple proof-of-concept JavaScript file that spawns the Windows Calculator app.
"I have confirmed that the node.exe packaged with the Adobe Customer Experience service can run any JavaScript you point it to," he explained to The Register.
[. . .] Security researchers commenting on Taggart's finding said they'd been under the impression the bundled Node runtime would only execute files signed by Adobe, but evidently that's not the case.
[. . .] "Because the JavaScript is getting invoked by path in C:\Program Files, it would be extremely difficult to detect from a monitoring/threat hunting perspective," explained Taggart, who added that he was able to get his own custom file dropper to run and execute a command-and-control agent without any warning from Windows Defender.
(Score: 5, Insightful) by RedGreen on Monday April 11 2022, @03:30AM (1 child)
Both virus delivery systems masquerading as software, has been so for decades. I have yet to figure out why people run their garbage. I certainly gave up on the Microsoft just about twenty-three years ago to the day, though it was earlyMay of 1999 when it happened. I know it was the 1999 when that wonderful Win98SE "upgrade" left my SB AWE 64 gold sound card only able to play a midi file no matter the Windows OS downgraded too. The Redhat 5.2 I bought allowed it to play audio just fine and I never ran Linux on a modem only a DSL connection, I got that the last day of April in that year, the "upgrade" was just after that. Adobe never have used their junk, flash never installed it, the .pdf files used other readers for that. And now I check I know the exact date May 4th, so probably couple days after that I got my hands on it, apparently this old brain still works....
https://winworldpc.com/product/windows-98/98-second-edition [winworldpc.com]
"Cervantes definitely was prescient in describing a senile Don fighting against windmills." -- larryjoe on /.
(Score: 2) by RedGreen on Wednesday April 13 2022, @05:48AM
Now I'm reminded of this thread by reading this. Seems they both had another shitload of exploits to patch.
https://www.theregister.com/2022/04/13/microsoft_patch_tuesday/ [theregister.com]
"Cervantes definitely was prescient in describing a senile Don fighting against windmills." -- larryjoe on /.