Anatomy of an Exploit: SMBGhost/CoronaBlue – How “Chompie” Achieved Unauthenticated Remote Code Execution Despite Windows 10’s Near Perfect Address Randomization

7/9/2020 12:00:00 PM [(UTC-05:00) Eastern Time (US & Canada)] - Can't make the live event? Register anyway to receive a link to the recording.

Show/Hide All Time Zones

All Time Zones

Dateline Standard Time-(UTC-12:00) International Date Line West 7/9/2020 4:00:00 AM
UTC-11-(UTC-11:00) Coordinated Universal Time-11 7/9/2020 5:00:00 AM
Aleutian Standard Time-(UTC-10:00) Aleutian Islands 7/9/2020 7:00:00 AM
Hawaiian Standard Time-(UTC-10:00) Hawaii 7/9/2020 6:00:00 AM
Marquesas Standard Time-(UTC-09:30) Marquesas Islands 7/9/2020 6:30:00 AM
Alaskan Standard Time-(UTC-09:00) Alaska 7/9/2020 8:00:00 AM
UTC-09-(UTC-09:00) Coordinated Universal Time-09 7/9/2020 7:00:00 AM
Pacific Standard Time (Mexico)-(UTC-08:00) Baja California 7/9/2020 9:00:00 AM
UTC-08-(UTC-08:00) Coordinated Universal Time-08 7/9/2020 8:00:00 AM
Pacific Standard Time-(UTC-08:00) Pacific Time (US & Canada) 7/9/2020 9:00:00 AM
US Mountain Standard Time-(UTC-07:00) Arizona 7/9/2020 9:00:00 AM
Mountain Standard Time (Mexico)-(UTC-07:00) Chihuahua, La Paz, Mazatlan 7/9/2020 10:00:00 AM
Mountain Standard Time-(UTC-07:00) Mountain Time (US & Canada) 7/9/2020 10:00:00 AM
Central America Standard Time-(UTC-06:00) Central America 7/9/2020 10:00:00 AM
Central Standard Time-(UTC-06:00) Central Time (US & Canada) 7/9/2020 11:00:00 AM
Easter Island Standard Time-(UTC-06:00) Easter Island 7/9/2020 10:00:00 AM
Central Standard Time (Mexico)-(UTC-06:00) Guadalajara, Mexico City, Monterrey 7/9/2020 11:00:00 AM
Canada Central Standard Time-(UTC-06:00) Saskatchewan 7/9/2020 10:00:00 AM
SA Pacific Standard Time-(UTC-05:00) Bogota, Lima, Quito, Rio Branco 7/9/2020 11:00:00 AM
Eastern Standard Time (Mexico)-(UTC-05:00) Chetumal 7/9/2020 11:00:00 AM
Eastern Standard Time-(UTC-05:00) Eastern Time (US & Canada) 7/9/2020 12:00:00 PM
Haiti Standard Time-(UTC-05:00) Haiti 7/9/2020 12:00:00 PM
Cuba Standard Time-(UTC-05:00) Havana 7/9/2020 12:00:00 PM
US Eastern Standard Time-(UTC-05:00) Indiana (East) 7/9/2020 12:00:00 PM
Turks And Caicos Standard Time-(UTC-05:00) Turks and Caicos 7/9/2020 12:00:00 PM
Paraguay Standard Time-(UTC-04:00) Asuncion 7/9/2020 12:00:00 PM
Atlantic Standard Time-(UTC-04:00) Atlantic Time (Canada) 7/9/2020 1:00:00 PM
Venezuela Standard Time-(UTC-04:00) Caracas 7/9/2020 12:00:00 PM
Central Brazilian Standard Time-(UTC-04:00) Cuiaba 7/9/2020 12:00:00 PM
SA Western Standard Time-(UTC-04:00) Georgetown, La Paz, Manaus, San Juan 7/9/2020 12:00:00 PM
Pacific SA Standard Time-(UTC-04:00) Santiago 7/9/2020 12:00:00 PM
Newfoundland Standard Time-(UTC-03:30) Newfoundland 7/9/2020 1:30:00 PM
Tocantins Standard Time-(UTC-03:00) Araguaina 7/9/2020 1:00:00 PM
E. South America Standard Time-(UTC-03:00) Brasilia 7/9/2020 1:00:00 PM
SA Eastern Standard Time-(UTC-03:00) Cayenne, Fortaleza 7/9/2020 1:00:00 PM
Argentina Standard Time-(UTC-03:00) City of Buenos Aires 7/9/2020 1:00:00 PM
Greenland Standard Time-(UTC-03:00) Greenland 7/9/2020 2:00:00 PM
Montevideo Standard Time-(UTC-03:00) Montevideo 7/9/2020 1:00:00 PM
Magallanes Standard Time-(UTC-03:00) Punta Arenas 7/9/2020 1:00:00 PM
Saint Pierre Standard Time-(UTC-03:00) Saint Pierre and Miquelon 7/9/2020 2:00:00 PM
Bahia Standard Time-(UTC-03:00) Salvador 7/9/2020 1:00:00 PM
UTC-02-(UTC-02:00) Coordinated Universal Time-02 7/9/2020 2:00:00 PM
Mid-Atlantic Standard Time-(UTC-02:00) Mid-Atlantic - Old 7/9/2020 3:00:00 PM
Azores Standard Time-(UTC-01:00) Azores 7/9/2020 4:00:00 PM
Cape Verde Standard Time-(UTC-01:00) Cabo Verde Is. 7/9/2020 3:00:00 PM
UTC-(UTC) Coordinated Universal Time 7/9/2020 4:00:00 PM
GMT Standard Time-(UTC+00:00) Dublin, Edinburgh, Lisbon, London 7/9/2020 5:00:00 PM
Greenwich Standard Time-(UTC+00:00) Monrovia, Reykjavik 7/9/2020 4:00:00 PM
Sao Tome Standard Time-(UTC+00:00) Sao Tome 7/9/2020 4:00:00 PM
Morocco Standard Time-(UTC+01:00) Casablanca 7/9/2020 5:00:00 PM
W. Europe Standard Time-(UTC+01:00) Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna 7/9/2020 6:00:00 PM
Central Europe Standard Time-(UTC+01:00) Belgrade, Bratislava, Budapest, Ljubljana, Prague 7/9/2020 6:00:00 PM
Romance Standard Time-(UTC+01:00) Brussels, Copenhagen, Madrid, Paris 7/9/2020 6:00:00 PM
Central European Standard Time-(UTC+01:00) Sarajevo, Skopje, Warsaw, Zagreb 7/9/2020 6:00:00 PM
W. Central Africa Standard Time-(UTC+01:00) West Central Africa 7/9/2020 5:00:00 PM
Jordan Standard Time-(UTC+02:00) Amman 7/9/2020 7:00:00 PM
GTB Standard Time-(UTC+02:00) Athens, Bucharest 7/9/2020 7:00:00 PM
Middle East Standard Time-(UTC+02:00) Beirut 7/9/2020 7:00:00 PM
Egypt Standard Time-(UTC+02:00) Cairo 7/9/2020 6:00:00 PM
E. Europe Standard Time-(UTC+02:00) Chisinau 7/9/2020 7:00:00 PM
Syria Standard Time-(UTC+02:00) Damascus 7/9/2020 7:00:00 PM
West Bank Standard Time-(UTC+02:00) Gaza, Hebron 7/9/2020 7:00:00 PM
South Africa Standard Time-(UTC+02:00) Harare, Pretoria 7/9/2020 6:00:00 PM
FLE Standard Time-(UTC+02:00) Helsinki, Kyiv, Riga, Sofia, Tallinn, Vilnius 7/9/2020 7:00:00 PM
Israel Standard Time-(UTC+02:00) Jerusalem 7/9/2020 7:00:00 PM
Kaliningrad Standard Time-(UTC+02:00) Kaliningrad 7/9/2020 6:00:00 PM
Sudan Standard Time-(UTC+02:00) Khartoum 7/9/2020 6:00:00 PM
Libya Standard Time-(UTC+02:00) Tripoli 7/9/2020 6:00:00 PM
Namibia Standard Time-(UTC+02:00) Windhoek 7/9/2020 6:00:00 PM
Arabic Standard Time-(UTC+03:00) Baghdad 7/9/2020 7:00:00 PM
Turkey Standard Time-(UTC+03:00) Istanbul 7/9/2020 7:00:00 PM
Arab Standard Time-(UTC+03:00) Kuwait, Riyadh 7/9/2020 7:00:00 PM
Belarus Standard Time-(UTC+03:00) Minsk 7/9/2020 7:00:00 PM
Russian Standard Time-(UTC+03:00) Moscow, St. Petersburg 7/9/2020 7:00:00 PM
E. Africa Standard Time-(UTC+03:00) Nairobi 7/9/2020 7:00:00 PM
Iran Standard Time-(UTC+03:30) Tehran 7/9/2020 8:30:00 PM
Arabian Standard Time-(UTC+04:00) Abu Dhabi, Muscat 7/9/2020 8:00:00 PM
Astrakhan Standard Time-(UTC+04:00) Astrakhan, Ulyanovsk 7/9/2020 8:00:00 PM
Azerbaijan Standard Time-(UTC+04:00) Baku 7/9/2020 8:00:00 PM
Russia Time Zone 3-(UTC+04:00) Izhevsk, Samara 7/9/2020 8:00:00 PM
Mauritius Standard Time-(UTC+04:00) Port Louis 7/9/2020 8:00:00 PM
Saratov Standard Time-(UTC+04:00) Saratov 7/9/2020 8:00:00 PM
Georgian Standard Time-(UTC+04:00) Tbilisi 7/9/2020 8:00:00 PM
Volgograd Standard Time-(UTC+04:00) Volgograd 7/9/2020 8:00:00 PM
Caucasus Standard Time-(UTC+04:00) Yerevan 7/9/2020 8:00:00 PM
Afghanistan Standard Time-(UTC+04:30) Kabul 7/9/2020 8:30:00 PM
West Asia Standard Time-(UTC+05:00) Ashgabat, Tashkent 7/9/2020 9:00:00 PM
Ekaterinburg Standard Time-(UTC+05:00) Ekaterinburg 7/9/2020 9:00:00 PM
Pakistan Standard Time-(UTC+05:00) Islamabad, Karachi 7/9/2020 9:00:00 PM
Qyzylorda Standard Time-(UTC+05:00) Qyzylorda 7/9/2020 9:00:00 PM
India Standard Time-(UTC+05:30) Chennai, Kolkata, Mumbai, New Delhi 7/9/2020 9:30:00 PM
Sri Lanka Standard Time-(UTC+05:30) Sri Jayawardenepura 7/9/2020 9:30:00 PM
Nepal Standard Time-(UTC+05:45) Kathmandu 7/9/2020 9:45:00 PM
Central Asia Standard Time-(UTC+06:00) Astana 7/9/2020 10:00:00 PM
Bangladesh Standard Time-(UTC+06:00) Dhaka 7/9/2020 10:00:00 PM
Omsk Standard Time-(UTC+06:00) Omsk 7/9/2020 10:00:00 PM
Myanmar Standard Time-(UTC+06:30) Yangon (Rangoon) 7/9/2020 10:30:00 PM
SE Asia Standard Time-(UTC+07:00) Bangkok, Hanoi, Jakarta 7/9/2020 11:00:00 PM
Altai Standard Time-(UTC+07:00) Barnaul, Gorno-Altaysk 7/9/2020 11:00:00 PM
W. Mongolia Standard Time-(UTC+07:00) Hovd 7/9/2020 11:00:00 PM
North Asia Standard Time-(UTC+07:00) Krasnoyarsk 7/9/2020 11:00:00 PM
N. Central Asia Standard Time-(UTC+07:00) Novosibirsk 7/9/2020 11:00:00 PM
Tomsk Standard Time-(UTC+07:00) Tomsk 7/9/2020 11:00:00 PM
China Standard Time-(UTC+08:00) Beijing, Chongqing, Hong Kong, Urumqi 7/10/2020 12:00:00 AM
North Asia East Standard Time-(UTC+08:00) Irkutsk 7/10/2020 12:00:00 AM
Singapore Standard Time-(UTC+08:00) Kuala Lumpur, Singapore 7/10/2020 12:00:00 AM
W. Australia Standard Time-(UTC+08:00) Perth 7/10/2020 12:00:00 AM
Taipei Standard Time-(UTC+08:00) Taipei 7/10/2020 12:00:00 AM
Ulaanbaatar Standard Time-(UTC+08:00) Ulaanbaatar 7/10/2020 12:00:00 AM
Aus Central W. Standard Time-(UTC+08:45) Eucla 7/10/2020 12:45:00 AM
Transbaikal Standard Time-(UTC+09:00) Chita 7/10/2020 1:00:00 AM
Tokyo Standard Time-(UTC+09:00) Osaka, Sapporo, Tokyo 7/10/2020 1:00:00 AM
North Korea Standard Time-(UTC+09:00) Pyongyang 7/10/2020 1:00:00 AM
Korea Standard Time-(UTC+09:00) Seoul 7/10/2020 1:00:00 AM
Yakutsk Standard Time-(UTC+09:00) Yakutsk 7/10/2020 1:00:00 AM
Cen. Australia Standard Time-(UTC+09:30) Adelaide 7/10/2020 1:30:00 AM
AUS Central Standard Time-(UTC+09:30) Darwin 7/10/2020 1:30:00 AM
E. Australia Standard Time-(UTC+10:00) Brisbane 7/10/2020 2:00:00 AM
AUS Eastern Standard Time-(UTC+10:00) Canberra, Melbourne, Sydney 7/10/2020 2:00:00 AM
West Pacific Standard Time-(UTC+10:00) Guam, Port Moresby 7/10/2020 2:00:00 AM
Tasmania Standard Time-(UTC+10:00) Hobart 7/10/2020 2:00:00 AM
Vladivostok Standard Time-(UTC+10:00) Vladivostok 7/10/2020 2:00:00 AM
Lord Howe Standard Time-(UTC+10:30) Lord Howe Island 7/10/2020 2:30:00 AM
Bougainville Standard Time-(UTC+11:00) Bougainville Island 7/10/2020 3:00:00 AM
Russia Time Zone 10-(UTC+11:00) Chokurdakh 7/10/2020 3:00:00 AM
Magadan Standard Time-(UTC+11:00) Magadan 7/10/2020 3:00:00 AM
Norfolk Standard Time-(UTC+11:00) Norfolk Island 7/10/2020 3:00:00 AM
Sakhalin Standard Time-(UTC+11:00) Sakhalin 7/10/2020 3:00:00 AM
Central Pacific Standard Time-(UTC+11:00) Solomon Is., New Caledonia 7/10/2020 3:00:00 AM
Russia Time Zone 11-(UTC+12:00) Anadyr, Petropavlovsk-Kamchatsky 7/10/2020 4:00:00 AM
New Zealand Standard Time-(UTC+12:00) Auckland, Wellington 7/10/2020 4:00:00 AM
UTC+12-(UTC+12:00) Coordinated Universal Time+12 7/10/2020 4:00:00 AM
Fiji Standard Time-(UTC+12:00) Fiji 7/10/2020 4:00:00 AM
Kamchatka Standard Time-(UTC+12:00) Petropavlovsk-Kamchatsky - Old 7/10/2020 5:00:00 AM
Chatham Islands Standard Time-(UTC+12:45) Chatham Islands 7/10/2020 4:45:00 AM
UTC+13-(UTC+13:00) Coordinated Universal Time+13 7/10/2020 5:00:00 AM
Tonga Standard Time-(UTC+13:00) Nuku'alofa 7/10/2020 5:00:00 AM
Samoa Standard Time-(UTC+13:00) Samoa 7/10/2020 5:00:00 AM
Line Islands Standard Time-(UTC+14:00) Kiritimati Island 7/10/2020 6:00:00 AM

Webinar Registration

Back in March, Microsoft patched CVE-2020-0796, known as SMBGhost or CoronaBlue, which affects Windows 10 and Windows Server 2019. The security hole is in the Server Message Block (SMB) protocol which Windows uses for file sharing and was also exploited with WannaCry. This was not an easy vulnerability to exploit to the full. For months the best researchers could accomplish was denial of service and local privilege elevation.

But just over a week ago, a proof of concept dropped that achieved the gold standard of exploitation:  unauthenticated, remote code exploitation (RCE).

In this webinar, we will dive into the details of SMBGhost and explain why security enhancements in Windows 10 and Windows Server 2019 make it so difficult to do RCE today and look at how security researchers were able to overcome it using “memory descriptor lists” which is a memory management object used in kernel drives to facilitate Direct Memory Access (DMA).

Then we will pivot to defense and discuss several different layers:

  • Patching (obvious)
  • Workarounds
  • Network based countermeasures
  • Network detection

Understanding this exploit from a network perspective is especially important and we will show you why this is more of an on-prem and cloud virtual network issue than an Internet facing issue. There are many opportunities to prevent this vulnerability from being exploited to spread laterally.

But we will also show how a many-layered defense-in-depth approach is always best because you can’t foresee and pre-empt every exploit, whether zero day or not. Besides a fully autonomous worm simply designed for denial-of-service, any other attacker will still need to connect back to C&C and usually exfiltrate data. And upstream from that, how does the attacker get initial access? Since this exploit is over SMB, in most cases the bad guy will need to use other methods at the beginning. In all such cases there is invariably several domain names and IP addresses involved.

Threat intel lists are nice for domains and IPs but that only identifies untargeted campaign infrastructure that’s been out long enough to get “burned”. On the other hand, Senior Security Researcher, Chad Anderson, of our sponsor, DomainTools, will briefly show you how their true machine learning predicts malicious domains and infrastructure before attacks happen, how to investigate these attacks, and predict an attacker's next move.

Please join us for this real training for free event.

First Name:   
Last Name:   
Work Email:  
Phone:  
Job Title:  
Organization:  
Country:    
State:  
 

Your information will be shared with the sponsor.

By clicking "Submit", you're agreeing to our Privacy Policy and consenting to be contacted by us.

 

 

Additional Resources