Windows 10: DoubleAgent zero-day hijacks Microsoft tool to turn antivirus into malware
From ZDNet
Thursday, March 23, 2017 by Uvah | Discussion: Windows Discussion
Came across this in yahoo news.
Reply #4 Friday, March 24, 2017 10:19 AM
Some sources say that the code had been leaked end of Jan and that it could be found on the DN for staggering price.
This is pretty worrying since it could be potentially an opened pandoras box.
Reply #5 Friday, March 24, 2017 1:50 PM
Eh? Did you guys watch the video?!
Am I missing something? He uses an ELEVATED cmd window to launch the DoubleAgent executable. Without admin privileges given to it by the user in the first place, DoubleAgent can't do anything. This 'zero-day exploit' is a joke.
Reply #6 Friday, March 24, 2017 2:20 PM
I read the article but didn't watch the video. Perhaps I should have.
Reply #7 Friday, March 24, 2017 3:35 PM
Eh? Did you guys watch the video?!
Am I missing something? He uses an ELEVATED cmd window to launch the DoubleAgent executable. Without admin privileges given to it by the user in the first place, DoubleAgent can't do anything. This 'zero-day exploit' is a joke.
the command prompt is launched as admin and might not even be necessary to be launched as such?'
You can run a regsvr without admin rights as far as im aware if you call another action to bypass.
Reply #8 Friday, March 24, 2017 3:36 PM
Not all...there are several AVs which have patched the vulnerability.
Please login to comment and/or vote for this skin.
Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:
- Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
- Access to a great community, with a massive database of many, many areas of interest.
- Access to contests & subscription offers like exclusive emails.
- It's simple, and FREE!







Reply #1 Thursday, March 23, 2017 6:57 PM
Ouch! A zero-day attack that targets almost ALL anti virus packages? That's an expensive process to engineer. I wonder if they stumbled onto another Stuxnet class critter.