Pre-Installed Password Manager On Windows 10 Lets Hackers Steal All Your Passwords

keeper-windows-10-password-manager-hacking

If you are running Windows 10 on your PC, then there are chances that your computer contains a pre-installed 3rd-party password manager app that lets attackers steal all your credentials remotely.

Starting from Windows 10 Anniversary Update (Version 1607), Microsoft added a new feature called Content Delivery Manager that silently installs new “suggested apps” without asking for users’ permission.

According to a blog post published Friday on Chromium Blog, Google Project Zero researcher Tavis Ormandy said he found a pre-installed famous password manager, called “Keeper,” on his freshly installed Windows 10 system which he downloaded directly from the Microsoft Developer Network.

Ormandy was not the only one who noticed the Keeper Password Manager. Some Reddit users complained about the hidden password manager about six months ago, one of which reported Keeper being installed on a virtual machine created with Windows 10 Pro.

Critical Flaw In Keeper Password Manager

Knowing that a third-party password manager now comes installed by default on Windows 10, Ormandy started testing the software and took no longer to discover a critical vulnerability that leads to “complete compromise of Keeper security, allowing any website to steal any password.”

“I don’t want to hear about how even a password manager with a trivial remote root that shares all your passwords with every website is better than nothing. People really tell me this,” Ormandy tweeted.

The security vulnerability in the Keeper Password Manager was almost identical to the one Ormandy discovered and reported in the non-bundled version of the same Keeper plugin in August 2016 that enabled malicious websites to steal passwords.

“I checked and, they’re doing the same thing again with this version. I think I’m being generous considering this a new issue that qualifies for a ninety day disclosure, as I literally just changed the selectors and the same attack works,” Ormandy said.

To explain the severity of the bug, Ormandy also provided a working proof-of-concept (PoC) exploit that steals a user’s Twitter password if it is stored in the Keeper app.

Install Updated Keeper Password Manager

Ormandy reported the vulnerability to the Keeper developers, who acknowledged the issue and released a fix in the just released version 11.4 on Friday by removing the vulnerable “add to existing” functionality.

Since the vulnerability only affects version 11 of the Keeper app, which was released on December 6 as a major browser extension update, the vulnerability is different from the one Ormandy reported six months ago.

Keeper has also added that the company has not noticed any attack using this security vulnerability in the wild.

As for Windows 10 users, Ormandy said users wouldn’t be vulnerable to the password theft unless they open Keeper password manager and enable the software to store their passwords.

However, Microsoft still needs to explain how the Keeper password manager gets installed on the users’ computers without their knowledge.

Meanwhile, users can use this registry tweak to disable Content Delivery Manager in order to prevent Microsoft from installing unwanted apps silently on their PCs.

APPLE-SA-2017-12-13-7 Additional information for APPLE-SA-2017-12-6-4 tvOS 11.2

Posted by Apple Product Security on Dec 15

APPLE-SA-2017-12-13-7 Additional information for
APPLE-SA-2017-12-6-4 tvOS 11.2

tvOS 11.2 addresses the following:

IOSurface
Available for: Apple TV 4K and Apple TV (4th generation)
Impact: An application may be able to execute arbitrary code with
kernel privileges
Description: A memory corruption issue was addressed with improved
memory handling.
CVE-2017-13861: Ian Beer of Google Project Zero

Kernel
Available for: Apple TV 4K and Apple TV…

Read more

Re: [oss-security] CVE-2017-17670: vlc: type conversion vulnerability

Posted by Stiepan on Dec 15

Nice job! By the way, when is back-porting of the fix to the current stable version(s) envisioned? (I doubt most oss OS
distributions use the “HEAD of the VLC master branch”, nor that most Windows or Mac users use the latest bleeding-edge
build, leaving a potentially large window for exploitation if former versions don’t get fixed; knowing VLC’s
popularity, I think that the question should be seriously considered)
And is…

Read more

APPLE-SA-2017-12-13-1 iOS 11.2.1

Posted by Apple Product Security on Dec 15

APPLE-SA-2017-12-13-1 iOS 11.2.1

iOS 11.2.1 is now available and addresses the following:

HomeKit
Available for: iPhone 5s and later, iPad Air and later, and iPod
touch 6th generation
Impact: A remote attacker may be able to unexpectedly alter
application state
Description: A message handling issue was addressed with improved
input validation.
CVE-2017-13903: Tian Zhang

Installation note:

This update is available through iTunes and Software…

Read more

APPLE-SA-2017-12-13-2 tvOS 11.2.1

Posted by Apple Product Security on Dec 15

APPLE-SA-2017-12-13-2 tvOS 11.2.1

tvOS 11.2.1 is now available and addresses the following:

HomeKit
Available for: Apple TV 4K and Apple TV (4th generation)
Impact: A remote attacker may be able to unexpectedly alter
application state
Description: A message handling issue was addressed with improved
input validation.
CVE-2017-13903: Tian Zhang

Installation note:

Apple TV will periodically check for software updates. Alternatively,
you may…

Read more

APPLE-SA-2017-12-13-3 iCloud for Windows 7.2

Posted by Apple Product Security on Dec 15

APPLE-SA-2017-12-13-3 iCloud for Windows 7.2

iCloud for Windows 7.2 is now available and addresses the following:

APNs Server
Available for: Windows 7 and later
Impact: An attacker in a privileged network position can track a user
Description: A privacy issue existed in the use of client
certificates. This issue was addressed through a revised protocol.
CVE-2017-13864: FURIOUSMAC Team of United States Naval Academy

WebKit
Available for:…

Read more

APPLE-SA-2017-12-13-4 iTunes 12.7.2 for Windows

Posted by Apple Product Security on Dec 15

APPLE-SA-2017-12-13-4 iTunes 12.7.2 for Windows

iTunes 12.7.2 for Windows addresses the following:

APNs Server
Available for: Windows 7 and later
Impact: An attacker in a privileged network position can track a user
Description: A privacy issue existed in the use of client
certificates. This issue was addressed through a revised protocol.
CVE-2017-13864: FURIOUSMAC Team of United States Naval Academy

WebKit
Available for: Windows 7 and later…

Read more

APPLE-SA-2017-12-13-5 Safari 11.0.2

Posted by Apple Product Security on Dec 15

APPLE-SA-2017-12-13-5 Safari 11.0.2

Safari 11.0.2 addresses the following:

WebKit
Available for: OS X El Capitan 10.11.6, macOS Sierra 10.12.6, and
macOS High Sierra 10.13.2
Impact: Processing maliciously crafted web content may lead to
arbitrary code execution
Description: Multiple memory corruption issues were addressed with
improved memory handling.
CVE-2017-7156: an anonymous researcher
CVE-2017-7157: an anonymous researcher
CVE-2017-13856:…

Read more

APPLE-SA-2017-12-13-6 Additional information for APPLE-SA-2017-12-6-2 iOS 11.2

Posted by Apple Product Security on Dec 15

APPLE-SA-2017-12-13-6 Additional information for
APPLE-SA-2017-12-6-2 iOS 11.2

iOS 11.2 addresses the following:

IOKit
Available for: iPhone 5s and later, iPad Air and later, and iPod
touch 6th generation
Impact: An application may be able to execute arbitrary code with
system privileges
Description: Multiple memory corruption issues were addressed through
improved state management.
CVE-2017-13847: Ian Beer of Google Project Zero…

Read more

SSD Advisory – vBulletin routestring Unauthenticated Remote Code Execution

Posted by Maor Shwartz on Dec 15

SSD Advisory – vBulletin routestring Unauthenticated Remote Code Execution

Full report: https://blogs.securiteam.com/index.php/archives/3569
Twitter: @SecuriTeam_SSD
Weibo: SecuriTeam_SSD

Vulnerability Summary
The following advisory describes a unauthenticated file inclusion
vulnerability that leads to remote code execution found in vBulletin
version 5.

vBulletin, also known as vB, is a widespread proprietary Internet forum
software package…

Read more

Software and Security Information