
DEF CON 32 - Sudos and Sudon’ts: Peering inside Sudo for Windows - Michael Torres
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 27:19
Microsoft's Pseudo for Windows enables Linux-like sudo functionality through UAC elevation but contains several security vulnerabilities 1:11-1:14.
Key Takeaways:
• Pseudo for Windows is a Rust-based tool that allows command line elevation while preserving input/output capabilities 1:21-1:25.
• The presenter found memory corruption issues despite Rust's memory safety, caused by unsafe Windows API calls 2:02-2:08.
• Cross-user code execution vulnerability allows unprivileged users to run code as another user via predictable RPC server names 17:21-17:25.
• Search order inconsistency could execute unintended commands from different directories 14:20-14:24.
• Microsoft fixed some issues but did not classify them as security vulnerabilities 2:05-2:06.
The tool demonstrates that even Rust applications can have memory issues when interacting with Windows native APIs 26:35-26:41.
Sources:
- 1:11-1:14 Introduction to Pseudo for Windows
- 1:21-1:25 Overview of Pseudo functionality
- 2:02-2:08 Memory corruption issues
- 14:20-14:24 Search order vulnerability
- 17:21-17:25 Cross-user code execution
- 26:35-26:41 Conclusion about Rust and Windows APIs
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
hey everybody how's it going my name is Michael Torres I'm going to be talking about uh pseudo for Windows title talk is pseudos and Pon here's a quick overview of what I'm going to talk about you can read so I'm not going to bore you too much but first we're going to go over what pseudo for Windows is because it sounds weird then we're going to hit uh some research initial research on it how it all works talk about some nonse issues according to msrc I'm supposed to use those uh then we're going to talk about some security issues that we found one of them's unfortunately still under embargo talk more about how I found that one later uh but let's hit it so who am I uh I do operational technology security at Google I also sort of do cyber depending on who you ask for the United States Marin…