Skip to content

Moderate VULN - OpenSSH_for_Windows_8.1p1 - Microsoft Office Security Feature Bypass #1964

Closed
@danielcunn123

Description

@danielcunn123

Prerequisites

  • Write a descriptive title.
  • Make sure you are able to repro it on the latest version
  • Search the existing issues.

Steps to reproduce

Step 1.) Create document.

Step 2.) Generate a random name for the document.

Step 3.) Retrieve document stored on remote device with 'Secure Shell Copy' application.

Step 4.) Open the document.

[PROTECTED VIEW BYPASS SUCCESSFUL]

VIDEO: - https://youtu.be/RN1t5_em8-I

Expected behavior

Documents obtained via the Secure Shell Copy utility open in protected view.

Actual behavior

Documents obtained via the Secure Shell Copy utility open in unprotected view, without a log of the event.

Error details

Documents obtained via web browsers require the end user to explicitly disable the 'protected' view for individual documents, rather than access documents via 'unprotected' view by default - with a 100% success rate.. No matter the file name nor location stored on the device.

Environment data

**REFERED BY secure@microsoft.com**


Tested on three system configurations:
No policy
Microsoft Windows 11 Security Baseline + MSOffice & apps + ADMX
STIG GPO Windows 11 Security Baseline + MSOffice & apps v2r4 + ADMX

Reproduceable with all GPO configurations.
The absolute path of C:\Windows\System32\OpenSSH\scp.exe was used, as its the same as typing scp in command/terminal window.

Note, this Document is shared within the same network and no documents are added to the 'Trusted Documents' nor 'Trusted Locations'.

Video demonstrates the generation of two documents on a Ubuntu machine within the same network, both documents with newly generated random file names. As shown, the document obtained via the Web browser on the Windows machine opens in protected view, whereas the Document obtained via Secure Shell Copy results in opening the document in unprotected view.

It is unsure why documents obtained via SSH are default trusted without a log, not requiring user interaction. This affects all Microsoft Office applications and file formats, not limited to Word.

Version

OpenSSH Version OpenSSH_for_Windows_8.1p1, LibreSSL 3.0.2 - Office Version 2205 (build 16.0.15225.20172) - Windows 10, 11 (build 17763.253, build 22000.675)

Visuals

filenames
doc1
doc2
doc1office
doc2office
reg
reg2

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions