Skip to content

Neutralize unexpected Utilman IFEO debugger during session start - #1553

Open
user-why-red wants to merge 1 commit into
SafeExamBrowser:masterfrom
user-why-red:master
Open

user-why-red wants to merge 1 commit into
SafeExamBrowser:masterfrom
user-why-red:master

Conversation

@user-why-red

Copy link
Copy Markdown

Note

AI was used as a helper.

  • Used to locate the fail path from a Runtime log ("EaseOfAccess.Verify" → "SessionIntegrityOperation").
  • Used to draft the neutralize/restore approach and the initial patch.
  • Behavior and review are mine: clear "Debugger" for the session, restore it on exit, do not whitelist Snipping Tool.
  • This pull request text is written by me.

Description

Session start currently aborts when

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Utilman.exe\Debugger"

is set to any non-empty value. On the machine that triggered this, the value was "C:\Windows\System32\SnippingTool.exe".

SEB logs "Ease of access configuration is compromised` and then fails in "SessionIntegrityOperation" with "Failed to ensure session integrity".

That value is an IFEO remap of Utilman (Win+U). It is not a Snipping Tool process blocklist. This PR does not allow that remap during an exam, because Win+U would start a screenshot tool.

When the SEB Service is not handling lockdown ("IgnoreService"), the runtime now deletes "Debugger" for the current session and restores the original value in "Revert()". If HKLM cannot be written, verification still fails. If the service is or will be active, the existing waiver is unchanged.

Changes

  • IRegistry: added "TryWrite" and "TryDelete".
  • Registry: implemented both methods, "TryOpenKey" can open a key writable.
  • EaseOfAccess: added "Neutralize()" and "Restore()". Neutralize deletes a non-empty Utilman "Debugger" and stores the previous value. Restore writes it back. The warning now includes the full registry key path.
  • ISystemSentinel / SystemSentinel: added "NeutralizeEaseOfAccess()" and "RestoreEaseOfAccess()".
  • SessionIntegrityOperation: after the existing service waiver, try neutralize and verify again. Restore on "Revert()".
  • Unit tests for neutralize success, neutralize failure, and restore on revert.

Additional Context

Relevant log:

WARNING: [SystemSentinel] Ease of access configuration is compromised: 'C:\Windows\System32\SnippingTool.exe'!
ERROR: Failed to ensure session integrity! Aborting session initialization...

Same registry value is also involved in leftover "SebDummy.exe" reports (#1118, discussion #1452). This PR only handles unexpected remaps when the service is ignored. It does not treat "SebDummy.exe" as always valid.

Session start aborted when Image File Execution Options\Utilman.exe
Debugger was set to a non-empty value such as SnippingTool.exe.

Do not allow that remap. Clear Debugger for the session when the SEB
Service is not handling lockdown, then restore the original value on
session end. If HKLM cannot be written, verification still fails.

Signed-off-by: Santhosh <santhosh.user.why.red@gmail.com>
@codecov

codecov Bot commented Sep 24, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 10.97561% with 73 lines in your changes missing coverage. Please review.
✅ Project coverage is 26.38%. Comparing base (4fa970f) to head (a34a3ca).

Files with missing lines Patch % Lines
...owser.Monitoring/System/Components/EaseOfAccess.cs 0.00% 36 Missing ⚠️
...eExamBrowser.SystemComponents/Registry/Registry.cs 0.00% 31 Missing ⚠️
...afeExamBrowser.Monitoring/System/SystemSentinel.cs 0.00% 6 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##           master    #1553      +/-   ##
==========================================
- Coverage   26.43%   26.38%   -0.05%     
==========================================
  Files         576      576              
  Lines       30219    30299      +80     
  Branches     3280     3290      +10     
==========================================
+ Hits         7987     7994       +7     
- Misses      21930    22006      +76     
+ Partials      302      299       -3     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant