Bug Hunter’s Grievance with Microsoft
Once again, a bug hunter has disclosed a vulnerability in Microsoft, disenchanted by their security measures. Ammar Askar acted swiftly and published a proof of concept (PoC) exploit for a flaw in Visual Studio Code (VS Code) merely an hour after informing an “old contact” on the open-source platform.
VS Code Flaw Uncovered
This exploit allows attackers to manipulate repositories, pushing shady VS Code extensions through Workspace Recommendations to steal OAuth tokens. These malicious actors can then interfere with both public and private GitHub repositories. Anyone who has experimented with github.dev, where you can access a GitHub repository using a browser-based VS Code, is at risk.
OAuth Tokens and Cunning Extensions
This sneaky function enables github.com to send an OAuth token to github.dev, but the token does not remain tied to the original repository. This means attackers can gain access to other repositories that the target is associated with. The key is to modify a repository’s .vscode/extensions.json file, introducing an attacker-supported extension for the browser-based VS Code. Typically, a warning would precede its installation, but these hackers have a Jupyter Notebook file prepared in the github.dev prior to its activation.
Jupyter Notebook and Deceptive Tactics
The hacker first convinces the target to open their repository with a github.dev link leading to this crafty ipynb file, which VS Code promptly opens in a Webview. Concealed within the Jupyter Notebook is an HTML snippet hiding in a Markdown cell, unleashing attacker-controlled JavaScript code. This illicit code mimics a keyboard shortcut, causing VS Code to deceptively accept the malicious extension popup. After that, it’s game over as the questionable extension operates with full browser access, capturing the OAuth token for malevolent purposes.
A Bug Hunter’s Discontent with Microsoft Security
Askar described his last experience with the Microsoft Security Response Center (MSRC) as a complete disaster. He noted that they discretely patched the bug he had highlighted without notifying him, claiming it had no security implications. Following that experience, he chose to publicly disclose any VSCode security bugs he might discover.
MSRC’s Mediocre Reaction
Examining a recent report by Starlabs on a VSCode XSS bug rated low severity and deemed ineligible, it appears MSRC has not stepped up regarding VSCode issues. Askar believes the VSCode team would have appreciated additional time to develop solutions, but he thinks this is one of the few moves he has to prompt MSRC and VSCode’s security enhancements. Investing time and effort into such exploits should not be overlooked.
Déjà Vu: The Saga of Nightmare Eclipse
Askar’s actions reflect the maneuvers of Nightmare Eclipse, another researcher thought to be a former Microsoft employee, who has gained a reputation for releasing zero-days without prior notice to Microsoft. To date, they have disclosed six zero-days, three of which are reportedly already being exploited by attackers.
Motives and Microsoft’s Reaction
Nightmare Eclipse suggested feeling betrayed and abandoned after a promise fell through. Microsoft engaged with its Digital Crimes Unit but quickly retreated after a storm of backlash.
GadgetLad made inquiries with Microsoft for additional information.
Conclusion: “Microsoft Gets Singed Once More”
And there you have it, everyone! Bug hunters are not hesitant to challenge MSRC when they feel neglected. It’s a tech drama filled with all the excitement, intrigue, and a touch of betrayal. Gadgets and devices just got a whole lot more thrilling, wouldn’t you agree?
