[HN Gopher] RedSun: System user access on Win 11/10 and Server w...
___________________________________________________________________
RedSun: System user access on Win 11/10 and Server with the April
2026 Update
Author : airhangerf15
Score : 170 points
Date : 2026-04-16 03:54 UTC (19 hours ago)
(HTM) web link (github.com)
(TXT) w3m dump (github.com)
| ranger_danger wrote:
| > normally I would just drop the PoC code and let people figure
| it out
|
| Looks like that's exactly what they did though?
|
| Or maybe they just meant that they don't usually explain how it
| works?
| kijin wrote:
| Tney gave it a sexy name and set up a website about it (a
| github repo, at any rate), instead of just talking about it in
| a mailing list and getting a CVE like a proper bearded security
| researcher.
| tclancy wrote:
| It's getting warm above the equator, they may have shaved for
| the season.
| egeozcan wrote:
| I wonder why Windows Defender has the privilege to alter the
| system files. Read them for analysis? Sure! Reset (as in, call
| some windows API to have it replaced with the original), why not?
| But being able to write sounds like a bad idea.
|
| However, I don't know what I'm talking about so take it with a
| grain of salt!
| EvanAnderson wrote:
| AV had traditionally run as SYSTEM on Windows (and, in the
| past, often had kernel mode drivers too). I've always thought
| it was a terrible idea. It opens up exciting new attack
| surfaces. Kaspersky and McAfee both had privilege escalation
| vulnerabilities that I can recall. There have been a ton in
| multiple products over the years.
| labelbabyjunior wrote:
| They kind of have to, though.
|
| If malware exploits a privilege escalation vuln, what's the
| AV going to do about it when it's reduced to the software
| equivalent of a UK police officer? Observe and report? Stop
| or I'll say "stop" again?
|
| AV requires great power, which requires great responsibility.
| The second part is what often eludes AV developers.
| EvanAnderson wrote:
| The OS should do the SYSTEM-level lifting and scanning
| processes and behavior analysis should run sandboxed as low
| priv processes. It would require a clearly defined API and
| I feel like MSFT was always reticent to commit, leaving AV
| manufacturers to create hacky nightmares.
| labelbabyjunior wrote:
| Well the OS should do nothing--remember MS was taken to
| court over that--but better privsep on the part of the
| AV, sure.
|
| Technically, Defender can be replaced with 3rd party AV.
| bux93 wrote:
| Windows has separate SeBackupPrivilege for backup software,
| so why not for AV?
| arcfour wrote:
| What would this privilege look like that is meaningfully
| different from SYSTEM while being properly protected
| from/able to deal with malware that has an LPE?
| formerly_proven wrote:
| "Because the remediation component requires SYSTEM, the
| entire AV needs to run as SYSTEM and we have to unpack
| malware in the kernel"
| Fokamul wrote:
| Because to get Ring0, you just need signed vulnerable driver.
|
| There are tons of signed drivers to explore ;-)
| labelbabyjunior wrote:
| Some files under Windows are protected as the TrustedInstaller
| user, which is a more restrictive level of permissions than
| SYSTEM.
| labelbabyjunior wrote:
| A local privilege escalation to root via an exploitable service?
|
| Doesn't Linux have one of these CVEs...each week?
| hsbauauvhabzb wrote:
| Probably, but is that service deployed as part of the base
| operating system or a third party package? Can you remove the
| service if you deem the crazy service behaviour is unnecessary
| or too risky for your usecase?
| hnlmorg wrote:
| Only if you're running daemons as root. Which would be an
| idiotic move to begin with because that's not how distros
| package their services. So you'd have to intentionally make
| this mistake.
| GuestFAUniverse wrote:
| Intentionally?
|
| Ignorance is bliss! Simply use docker in its (old) default
| setup, instead of podman, apptainer, docker-rootless ... and
| that world is yours.
|
| Added bonuses are the incredible stupid integration with ufw
| on Ubuntu, images with laughable uid mapping, ...
|
| How that shit got traction baffles me.
| hnlmorg wrote:
| That's just the docker daemon. The actual docker services
| would (or at least _should_ ) still be running as its own
| user/group just like they would if you were running them on
| the host.
|
| And that's exactly how any reputable image would be built.
| BodyCulture wrote:
| No.
| IshKebab wrote:
| Not quite every week, but yeah it has a lot. And if the target
| uses sudo at all you don't even need an exploit!
|
| But nobody mentioned Linux. There's no need for whataboutism.
| They both shouldn't have these vulnerabilities.
| hnlmorg wrote:
| > And if the target uses sudo at all you don't even need an
| exploit!
|
| Why would a target executable use sudo? There are proper
| mechanisms for automated elevation of permissions and sudo
| isn't it.
|
| sudo is designed for user interactivity. And by default
| prompts for a password. However some people get lazy and
| disable the password entry requirement.
| IshKebab wrote:
| A target _user_. If you get local code execution on the
| account of a user that uses sudo you can trivially got
| root. Doesn 't matter if they disabled the password
| authentication or not.
| hnlmorg wrote:
| Of course it matters if they disabled password
| authentication. If you require password authentication
| when running sudo then an attacker has to find a RCE
| exploit _and then_ crack a password. Which is waaay
| beyond any effort the average attacker is willing to
| invest. Because At that point, root access isn't really
| worth the effort.
|
| An attacker will probably just use the host for sending
| spam emails, bot / DDoS traffic or look for other daemons
| they can jump to which weren't web accessible (eg a
| database).
|
| And furthermore, if you've got a RCE in a daemon then
| that code is the running as the daemons' user. Which
| shouldn't be in the sudoers file (eg wheel group) to
| begin with.
| hathym wrote:
| cl /std:c++17 /EHsc /W4 /O2 /DUNICODE /D_UNICODE /wd4005
| /Fe:RedSun.exe RedSun.cpp advapi32.lib ole32.lib user32.lib
| technion wrote:
| Seriously this is my bugbear with code for windows: how did you
| figure that invocation out?
|
| Anything for Linux you just type "make". If the author skipped
| a makefile, theres rarely much to it.
|
| But when someone has a cpp file for Windows it looks like this.
| IFC_LLC wrote:
| I remember the times when Microsoft had a lot of problems 20
| years ago because of Sasser and other viruses that were taking
| over Windows. They did not have any contenders. Yet they have
| stopped any software development for 9 months just to re-work
| their entire codebase to prevent things like direct memory
| execution and stuff like that. The result of that was Windows XP
| Service Pack 2. After that thing windows XP became a legend.
|
| Now, when Linux is slowly creeping on one side, and Mac NEO on
| another they keep releasing this AI-slop.
|
| By the looks of it they make most of their money from the cloud
| and other software things nowadays. And Windows has become a
| sidekick in their processes.
| nailer wrote:
| > Windows XP Service Pack 2. After that thing windows XP became
| a legend.
|
| God that was an era. XP SP2 was a great OS, IE was the best
| browser, MSN was the most popular messenger, Skype was
| acquired, HTC's Windows CE devices were shipping real web
| browsers that worked over 3G.
|
| By the end of the Ballmer era, Microsoft has lost the OS, the
| browser, the messenger, the meeting service and mobile.
| uep wrote:
| I agree with you on everything except the browser. I'm pretty
| sure I was using Firefox (or maybe Opera?) on Windows before
| the release of Vista. I know I was still using IE for some
| ActiveX web apps for a while. This was the era that I
| switched over to Linux full-time, but both Windows 2000 and
| XP were great OSes at this time. Linux was painful to adopt,
| but I really loved the promise of "full-control" over my
| computer.
|
| My peeve today is how bad modern chat programs feel compared
| to the old instant messengers. The modern programs all feel
| slow and clunky in comparison. I felt that all of the
| messengers I used (MSN, AIM, ICQ) were more responsive than
| their modern day equivalents.
| IFC_LLC wrote:
| Boy oh boy, have we forgotten the Maxthon?
| https://en.wikipedia.org/wiki/Maxthon
|
| I remember the times when IE passed ACID test? Do we
| remember the ACID? http://acid2.acidtests.org/#top
|
| Ah, what the times were those. Firefox was just gaining
| traction.
|
| And I agree. Slack is sitting there, consuming over gig of
| memory on my computer, and Miranda NG was able to do the
| same functionality with cool skins and just 30 megs of ram.
|
| Skins... Skins... We've lost even those...
| hulitu wrote:
| > Boy oh boy, have we forgotten the Maxthon?
|
| Never heard about it (Europe).
| IFC_LLC wrote:
| https://gs.statcounter.com/browser-market-
| share#monthly-2009...
|
| Yes, I've just checked, even in 2009 you still have IE over
| 64% of browser usage.
| uep wrote:
| They said IE was the best browser, not the most popular.
| I wouldn't dispute that IE was more commonly used at the
| time.
|
| Just checked your link and this fits with what I thought
| in terms of marketshare. You can see that Firefox was
| ~25% of marketshare in 2009. Which is an enormous share
| of the pie when you consider that they couldn't stick a
| download link on the front page of the most dominant
| search engine, and it didn't come preinstalled.
|
| Never used Maxthon.
|
| Damn, this also reminded me that RSS feeds were
| everywhere back then, and the browser supported it
| directly.
| IFC_LLC wrote:
| Oh don't tell me about Nero, Winamp, eMule, Download
| managers, auto-dialers, free internet on Saturdays after
| 2am till 9am, miranda NG, PHPBB, etc.
|
| The internet was awesome.
| nailer wrote:
| > They said IE was the best browser, not the most
| popular.
|
| TBF I should have said 'most popular' for all those
| categories.
| toyg wrote:
| I don't think SP2 made much of a difference in the popularity
| of XP. It was already dominant, and it's mostly remembered as
| "legendary" because it had become the target platform for every
| hardware and software vendor on the planet. Windows 98 was too
| flaky to engender any serious friction to upgrades, and Windows
| 2000 was not consumer-friendly enough; XP effectively unified
| the consumer and professional desktop markets, and became the
| gold standard.
|
| SP2, if anything, _slowed down_ adoption, since it threw a
| bunch of spanners in the way of third-party code. It was
| probably necessary, just to stem the flow of bad press, but no
| mean a key in XP 's overall success.
| IFC_LLC wrote:
| It was not that bad. I remember when SP fixed a bunch of
| issues with bluetooth, and windows CD burning program was
| better than any of the Nero Burning ROMs, cause those became
| unusable overbloated.
| steve1977 wrote:
| Also, technically XP was Windows NT 5.1, so it was built on a
| solid basis.
|
| Whereas 98 was still in the kinda DOS-based 9x line.
|
| And I fully agree with you to not mention Windows Me.
| hulitu wrote:
| > I don't think SP2 made much of a difference in the
| popularity of XP
|
| The general knowledge was to wait until the SP were stable.
| This was hard. 4.0 had SP6, 2k had SP4.
| orbital-decay wrote:
| There were several points in time (after the SP2 too) when
| installing WinXP with an active internet connection was nearly
| impossible, because it would get infected during the
| installation and shut itself down halfway through it.
| luma wrote:
| Tried to download and Defender blocks it.
| trollbridge wrote:
| That's how the exploit works.
| luma wrote:
| I can't seem to find any system files replaced, and the .exe
| was never executed. I'm running this in a test VM, but from
| what I can see, Defender signatures have been updated to
| block this prior to execution.
|
| The exploit, from my reading, needs to be executed in order
| to do it's thing, but Defender isn't allowing it to be
| written to the filesystem on download.
| molticrystal wrote:
| What is Defender marking it as? I also wonder if they are
| just special casing this program and it would work again if
| the code was shuffled a bit or if it used the AMSI sig [0]
| instead of EICAR or if they actually fixed the problem.
|
| [0] https://github.com/Roadmvn/C-Full-Offensive-
| Course/blob/main...
| luma wrote:
| Detected: Program:Win32/Wacapew.C!ml
|
| With a link to: https://www.microsoft.com/en-
| us/wdsi/threats/malware-encyclo...
| lexicality wrote:
| helpfully the user provides a second tool which automatically
| turns off Windows Defender so you can't be affected by this:
| https://github.com/Nightmare-Eclipse/UnDefend
| layer8 wrote:
| > It runs in two modes, passive and aggressive
|
| Lol
| hulitu wrote:
| Unlike Windows Defender which is passive aggressive.
| Implement7347 wrote:
| I'd love to think that this person is a rogue AI, (better than
| Claude mythos?) Dropping two zero days in one month is pretty
| interesting. Nice work.
| Dwedit wrote:
| Any way to disable the entire cloud tag system?
___________________________________________________________________
(page generated 2026-04-16 23:01 UTC)