Windows 10 Store 'wsreset' tool lets attackers bypass antivirus

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,176
A technique that exploits Windows 10 Microsoft Store called 'wsreset.exe' can delete bypass antivirus protection on a host without being detected.

Wsreset.exe is a legitimate troubleshooting tool that lets users diagnose problems with the Windows Store and reset its cache.

Pentester and researcher Daniel Gebert has discovered that wsreset.exe can be abused to delete arbitrary files.

As wsreset.exe runs with elevated privileges because it deals with Windows settings, this bug would allow attackers to delete files even if they would not normally have the privileges.
The researcher demonstrated how this behavior could be abused to bypass antivirus protections, focusing on Adaware antivirus as an example. [...]
 

SeriousHoax

Level 47
Verified
Top Poster
Well-known
Mar 16, 2019
3,635
Sounds like another case why UAC should be always on maximum.
And of course SRP
Looks like this can bypass UAC at maximum.
As wsreset.exe runs with elevated privileges because it deals with Windows settings, this bug would allow attackers to delete files even if they would not normally have the privileges.
 

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,140
This technique depends on the autoelevate feature of WSReset.exe. Any such bypass is blocked by UAC “Always Notify” setting. I confirmed it on my computer by using PowerShell POC:
 

show-Zi

Level 36
Verified
Top Poster
Well-known
Jan 28, 2018
2,463
Microsoft Store should distribute 'Anti wsreset tool'o_O
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top