
DEF CON 32 - QuickShell Sharing is caring abt RCE attack chain on QuickShare - Or Yair, Shmuel Cohen
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 45:09
[Quick Share on Windows enables remote code execution via a creative attack chain combining file acceptance bypass, rogue Wi-Fi connection, and exploitation of Chrome's download process, leveraging metadata to identify and overwrite installers 19:10-38:48.]
Key Takeaways:
• File acceptance bypass allows sending files without user approval, bypassing visibility modes 19:10.
• Rogue Wi-Fi connection can be maintained by crashing Quick Share, enabling man-in-the-middle access to victim traffic for 30+ seconds 22:45-27:54.
• Metadata from HTTPS traffic (domains and file sizes) enables precise detection of executable downloads (e.g., VS Code, Notepad++) 30:05-33:27.
• A persistent timeout vulnerability causes Quick Share to endlessly open files, preventing Chrome from overwriting malicious files during download 36:46-37:59.
The research demonstrates how basic vulnerabilities can be chained into a powerful remote code execution attack, highlighting the importance of addressing non-critical bugs that enable broader exploitation paths. All 10 vulnerabilities were reported to Google, which confirmed and patched them with two CVEs.
Sources:
- 19:10 File acceptance bypass and visibility mode bypass explained.
- 22:45-27:54 Rogue Wi-Fi attack chain and stable connection via crash.
- 30:05-33:27 Use of HTTPS metadata to identify executable downloads.
- 36:46-37:59 Timeout vulnerability used to prevent Chrome from overwriting malicious files.
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
I'd like to introduce Ora and here we go and away we go okay hi everyone today we will present quick show sharing is caring about an RC attack chain on Quick Share so my name is Ora I'm the security research team lead at safe Bri I have more than six years experience in security research my past research included some research on Linux environments embedded and embedded devices Android devices and more and for more than 3 years now my main focus lies in vulnerability research in the Windows operating system and third party apps that run on it hi everyone my name is sh Coen and I'm excited to be here today and present the finding of our recent research little bit about myself I have six years of experience in the cyber security industry previously I conducted AP malare research within the c…