Exposure can bypass the lock screen? Sogou input method slams Microsoft Windows vulnerability.

According to Cailian, some citizens have recently received a notice from their work units, requesting to uninstall the sogou input method. The vulnerability report shows that some versions of sogou input method can bypass the password and gain system permissions. Sogou input method responded that the problem was caused by Microsoft screen keyboard and other related programs actively loading Chinese input method with privileged interface.

According to a vulnerability report from Sheng Bang Security in the National Information Security Vulnerability Database, under the Microsoft Windows operating system, an attacker can bypass the system login password through a partial version of the sogou input method, and execute the CMD command while the screen is locked, so as to gain the local system authority.

It is understood that an attacker can use this vulnerability to directly reset the administrator password without knowing the user name and password of the target machine through some remote control programs.

According to the circular, the vulnerability stems from the fact that the system has too high permission to run the sogou input method, so that the sogou input method can run without authorization, and the sogou input method’s own permission verification is not rigorous. After successfully exploiting the vulnerability, the attacker can execute arbitrary commands on the target system.

It is suggested in the bulletin that you should pay attention to the manufacturer’s update and upgrade the version in time. Before the official release of the new version, it is suggested to uninstall the sogou input method and replace it with other input methods.

In this regard, sogou input method responded yesterday that after investigation by the security team, the problem only existed in a specific version of Windows system, which was caused by Microsoft’s on-screen keyboard and other related programs actively loading Chinese input method with privileged interface. "We have informed the relevant Microsoft team of this system vulnerability."

"Before Microsoft fixes the vulnerability, in order to protect users’ safety more effectively, we have taken active evasive measures, and sogou input method will voluntarily quit loading and execution under the Windows login interface." Sogou input method added.

IT House found that there are many tutorials circulating on the Internet that bypass the screen lock, including the "Game Center" section of sogou input method, which can directly pop up the game center window on the Windows screen lock interface and open the QQ download interface. Open the Windows system file manager by downloading QQ, and then you can open the CMD window.

This article is from: IT House

Reporting/feedback