Repository navigation
Neutralize unexpected Utilman IFEO debugger during session start - #1553
Open
user-why-red wants to merge 1 commit into
Open
user-why-red wants to merge 1 commit into
user-why-red wants to merge 1 commit into
Conversation
Session start aborted when Image File Execution Options\Utilman.exe Debugger was set to a non-empty value such as SnippingTool.exe. Do not allow that remap. Clear Debugger for the session when the SEB Service is not handling lockdown, then restore the original value on session end. If HKLM cannot be written, verification still fails. Signed-off-by: Santhosh <santhosh.user.why.red@gmail.com>
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## master #1553 +/- ##
==========================================
- Coverage 26.43% 26.38% -0.05%
==========================================
Files 576 576
Lines 30219 30299 +80
Branches 3280 3290 +10
==========================================
+ Hits 7987 7994 +7
- Misses 21930 22006 +76
+ Partials 302 299 -3 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Note
AI was used as a helper.
Description
Session start currently aborts when
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Utilman.exe\Debugger"
is set to any non-empty value. On the machine that triggered this, the value was "C:\Windows\System32\SnippingTool.exe".
SEB logs "Ease of access configuration is compromised` and then fails in "SessionIntegrityOperation" with "Failed to ensure session integrity".
That value is an IFEO remap of Utilman (Win+U). It is not a Snipping Tool process blocklist. This PR does not allow that remap during an exam, because Win+U would start a screenshot tool.
When the SEB Service is not handling lockdown ("IgnoreService"), the runtime now deletes "Debugger" for the current session and restores the original value in "Revert()". If HKLM cannot be written, verification still fails. If the service is or will be active, the existing waiver is unchanged.
Changes
Additional Context
Relevant log:
WARNING: [SystemSentinel] Ease of access configuration is compromised: 'C:\Windows\System32\SnippingTool.exe'!
ERROR: Failed to ensure session integrity! Aborting session initialization...
Same registry value is also involved in leftover "SebDummy.exe" reports (#1118, discussion #1452). This PR only handles unexpected remaps when the service is ignored. It does not treat "SebDummy.exe" as always valid.