Connect with us
X
Categories:

Technology

Security researchers criticize CrowdStrike for operating a “ridiculous” bug bounty disclosure program

Published

on

Security researchers criticize CrowdStrike for operating a “ridiculous” bug bounty disclosure program
Share this post:

The vulnerability might not be noteworthy, but the reporting process may be.

A security firm has criticized CrowdStrike for operating a “ridiculous” bug bounty disclosure program following a sensor flaw report.

In April, Pascal Zenker, a partner of Swiss security analyst service Modzero AG, discovered a vulnerability in CrowdStrike Falcon Sensor, agent software used to transmit data to the Falcon endpoint security platform.

The vulnerability, tracked as CVE-2022-2841, allowed attackers to exploit and bypass the one-time generated token check used to uninstall the sensors on Windows devices, thereby cutting security event data streams and potentially leaving the machine vulnerable to further compromise by malware.

The team created an automated proof-of-concept (PoC) tool to corrupt the sensor and ignore the token check in Falcon versions 6.31.14505.0 and 6.42.15610.

However, the attacker already needed administrator privileges to achieve this security bypass, relegating the potentially high-risk vulnerability to a low-severity issue.

Modzero says the bug wasn’t “worth a tweet” as the “overall risk of the vulnerability is very limited”, however, the alleged response of CrowdStrike was worth commenting on.

“We’d like to shed some light on a ridiculous vulnerability disclosure process with CrowdStrike,” the company tweeted.

Third-party program

According to a security advisory published Monday (August 22), Modzero expected a clean-cut vulnerability disclosure process from the Nasdaq-listed IT firm. However, Modzero says the “communication and disclosure with CrowdStrike was tedious and turned unprofessional in the end”.

CrowdStrike runs its bug bounty program through HackerOne. The bone of contention appeared that CrowdStrike wanted Modzero to submit the vulnerability through the program. Still, the company did not want to agree to the program’s terms, which were said to include signing a mutual non-disclosure agreement.

Modzero said it requested a direct security contact outside of HackerOne, and after months of emails, the company submitted a draft security advisory in late June, together with a PoC.

CrowdStrike said bug replication had not been possible on more recent software versions. Modzero requested a trial version of the latest software, which was allegedly denied.

“As the issue was not considered valid, we informed CrowdStrike that we would release the advisory to the public,” Modzero commented.

“In response, CrowdStrike tried again to set up a bug bounty disclosure meeting between ‘Modzero’s sr Leadership and CrowdStrike CISO […] to discuss [the] next steps related to the bug bounty disclosure’ in contrast to our previously stated disclosure rules.”

Modzero said it then acquired a recent version of the software and verified the vulnerability still existed. However, the exploit code had been flagged as malicious – an alleged change that was easily remedied by tweaking the exploit code.

Advisory published

Modzero has since published the security advisory, criticizing the cybersecurity firm for being inflexible outside its “NDA-ridden bug bounty program”.

“[We concluded] that CrowdStrike tried to ‘fix’ the issue while being told the issue didn’t exist. Which is pretty disrespectful to us,” Modzero commented.

RECOMMENDED  Bug Bounty Radar: November 2022's newest bug bounty programs

When approached for comment, CrowdStrike directed us to a statement posted on Reddit on Monday (August 22) that links back to Modzero’s advisory.

The cybersecurity firm says that the main problem is a fail-open condition in the Microsoft Installer (MSI) harness, and the issue has been reported to the relevant parties.

According to the company, controlling it would require moving away from the MSI framework. The vulnerability could only be exploited with specialized software, local admin access, privilege elevation, and an endpoint reboot.

CrowdStrike informed customers in July.

“Detection logic was also added to the sensor to try to detect this technique and similar ones,” CrowdStrike added. “We thank Modzero for their hard work and disclosure of this incident.”

Following the publication of this article, CrowdStrike spokesperson Kevin Benacci told Daily Swig:

We want to set the record straight on how this situation transpired. As both parties have stated, we engaged with Modzero immediately upon receipt of them reporting the issue on June 29. As Modzero has indicated, the issue reported is with Microsoft’s MSI implementation and requires local access and admin privileges.

On July 8, less than 10 days of receipt of this initial report, we notified all Falcon customers via a Technical Alert (crediting Modzero), and we subsequently reported the MSI bug to Microsoft. We attempted to continue the dialogue with Modzero in early July to no avail and did not hear from them over the past six plus weeks until yesterday, when they published their blog. In line with industry best practices, we are committed to engaging with the research community in a positive and professional manner that protects customers.

Responsible and timely disclosure is an important part of the process of building trust and supporting the security community, which is why CrowdStrike runs an open and transparent bug bounty program with partners such as HackerOne.


Get More Stories Like This On: Facebook: @AllNaijaEntertainment, Twitter: @AllNaijaEntertainment
Huawei Watch GT 4 provides new health features in beta update
Technology7 hours ago

Huawei Watch GT 4 provides new health features in beta update

Oraimo Toast 10 Byte 10000mAh 10.5W Power Bank
Technology9 hours ago

All Oraimo 10000 mAh Power Banks Reviews, Price, How to Buy, FREE COUPON CODES!

Oraimo PowerBox 600 60000mAh 22.5W Power Bank
Technology10 hours ago

All Oraimo Power Banks Reviews, Price, How to Buy, FREE PROMO CODES!

Oraimo logo
Technology10 hours ago

How to Order for Oraimo Products Online

Tesla Optimus robot can now use AI to communicate as well as build a hive mind and charge itself
Technology12 hours ago

Tesla Optimus robot can now use AI to communicate as well as build a hive mind and charge itself

Ruben Amorim responds to rumours he could replace Pep Guardiola
Sports13 hours ago

Ruben Amorim responds to rumours he could replace Pep Guardiola

Sabatino Durante reveals Manchester United transfer interest in Richard Rios
Sports14 hours ago

Sabatino Durante reveals Manchester United transfer interest in Richard Rios

Kidnappers abduct journalist after publishing human rights violation story
News14 hours ago

Kidnappers abduct journalist after publishing human rights violation story

NDDC seeks UAE collaboration on youth development, health and education
News14 hours ago

NDDC seeks UAE collaboration on youth development, health and education

Peres & Beckham
ANE Football Analytical14 hours ago

How Ronaldinho, Beckham, and Ronaldo’s Transfers in 2003 Shaped the Future of Football

Nigerians not enjoying this govt — Bala Mohammed
News15 hours ago

Nigerians not enjoying this govt — Bala Mohammed

Vinicius Jnr Bellingham Balon Dor
ANE Football Analytical15 hours ago

Ballon d’Or Nominees 2024 vs. 2004: A Nostalgic Bias or Fair Comparison?

MetLife - New Jersey, Home of the New York Giants and New York Jets (NFL)
ANE Football Analytical15 hours ago

2025 FIFA Club World Cup: Venues, Teams, and Final Set for MetLife Stadium

Hold VeryDarkMan responsible — Bobrisky to Falana, Falz
Entertainment15 hours ago

Hold VeryDarkMan responsible — Bobrisky to Falana, Falz

Fergie, Pep, Mourinho, Don Carlo, or Zizou. Which was the Hardest to Achieve?
ANE Football Analytical16 hours ago

Fergie, Pep, Mourinho, Don Carlo, or Zizou. Which was the Hardest to Achieve?

Nigeria-Igbo Epic film, 'Ekpebiwo M' premieres this November
Entertainment16 hours ago

Nigeria-Igbo Epic film, ‘Ekpebiwo M’ premieres this November

Davido proclaims 'Timeless' his best album
Entertainment17 hours ago

Davido proclaims ‘Timeless’ his best album

Liam Payne passes away following a fall from the third storey of a hotel
Entertainment19 hours ago

Liam Payne passes away following a fall from the third storey of a hotel

Insta360 Ace Pro 2 launch date confirmed
Technology1 day ago

Insta360 Ace Pro 2 launch date confirmed

Artificial intelligence "tongue" can distinguish between Pepsi and Coke
Technology1 day ago

Artificial intelligence “tongue” can distinguish between Pepsi and Coke

News1 day ago

NDLEA Ebonyi arrests 149 suspects and confiscates 115 kg of illegal substances in Q3 2024

Manchester United "barred" Sir Alex Ferguson from the players' dressing room
Sports1 day ago

Manchester United “barred” Sir Alex Ferguson from the players’ dressing room

Raphael Varane explains why he felt he had to leave Manchester United
Sports1 day ago

Raphael Varane explains why he felt he had to leave Manchester United

Senate launches an investigation on fake news about Akpabio’s impeachment
News2 days ago

Senate launches an investigation on fake news about Akpabio’s impeachment

Elon Musk donates close to $75M to Trump’s presidential campaign
News2 days ago

Elon Musk donates close to $75M to Trump’s presidential campaign

I've never been attracted to an actor so to speak — Actress Bimbo Akintola
Entertainment2 days ago

I’ve never been attracted to an actor so to speak — Actress Bimbo Akintola

Many people we call “ogbanje” are spiritually gifted — Actor Yul Edochie
Entertainment2 days ago

Many people we call “ogbanje” are spiritually gifted — Actor Yul Edochie

Hold VeryDarkMan responsible — Bobrisky to Falana, Falz
Entertainment2 days ago

Falana, Falz give Bobrisky 12-hour ultimatum to apologise, retract defamatory claims

Huawei Mate 70 series rumored to feature dual OS options
Technology2 days ago

Huawei Mate 70 series rumored to feature dual OS options

OPPO Reno13 Pro expected to gain additional flagship-grade features
Technology2 days ago

OPPO Reno13 Pro expected to gain additional flagship-grade features

Harry Kane reacts to Thomas Tuchel link with England manager job
Sports2 days ago

Harry Kane reacts to Thomas Tuchel link with England manager job

A British boxer was arrested by airport security after smashing a fan's phone in a fit of rage
Sports2 days ago

A British boxer was arrested by airport security after smashing a fan’s phone in a fit of rage

EFCC
News2 days ago

EFCC arrests radio host over N700m Ponzi scheme

EFCC
News2 days ago

Court stops EFCC from arresting ex-defence minister Batagarawa

Oba Adedotun Gbadebo cautions Ogun booksellers on piracy
News2 days ago

Oba Adedotun Gbadebo cautions Ogun booksellers on piracy

Mr Macaroni responds to the controversial video of children reenacting his skit
Entertainment2 days ago

Mr Macaroni responds to the controversial video of children reenacting his skit

I regret not having baby mamas — Singer Skales
Entertainment2 days ago

I regret not having baby mamas — Singer Skales

Remove defamatory posts on Falana, Falz — Court orders VDM
Entertainment2 days ago

Remove defamatory posts on Falana, Falz — Court orders VDM

probable look at Samsung Galaxy Z Fold6 Special Edition and Samsung W25 — Leaker
Technology3 days ago

Probable look at Samsung Galaxy Z Fold6 Special Edition and Samsung W25 — Leaker

Serious warning to Android users to stop downloading malicious apps
Technology3 days ago

Serious warning to Android users to stop downloading malicious apps

Ogun State gov unveils subsidised rice sales
News7 days ago

Ogun State gov unveils subsidised rice sales

Border security: Customs to combat smuggling with technology
News7 days ago

Border security: Customs to combat smuggling with technology

Bob Manuel Udokwu reacts to people calling him their 'crush'
Entertainment7 days ago

Bob Manuel Udokwu reacts to people calling him their ‘crush’

Gabriella Cilmi hit has barely aged 16 years after debut
Entertainment7 days ago

Gabriella Cilmi hit has barely aged 16 years after debut

Nobel Laureate award exposed me to danger — Prof. Wole Soyinka
News7 days ago

Nobel Laureate award exposed me to danger — Prof. Wole Soyinka

I’ve never had N1m in my account — BBN winner Kellyrae
Entertainment6 days ago

I’ve never had N1m in my account — BBN winner Kellyrae

Reason behind Bukayo Saka's absence from tonight's England match against Finland
Sports6 days ago

Bukayo Saka withdraws from England squad as Arsenal face anxious injury

Rasmus Hojlund urges his manager not to give him 90 minutes amid injury fears
Sports6 days ago

Rasmus Hojlund urges his manager not to give him 90 minutes amid injury fears

Wayback Machine hack reveals 31,000,000 people's personal details
Technology7 days ago

Wayback Machine hack reveals 31,000,000 people’s personal details

Fear as TikTok influencer Salo shot in Lagos
Entertainment6 days ago

Fear as TikTok influencer Salo shot in Lagos

Liam Payne ‘delays second solo album’ due to personal issue
Entertainment7 days ago

Liam Payne ‘delays second solo album’ due to personal issue

Garmin releases new update for all Forerunner smartwatches with fresh bug patch
Technology7 days ago

Garmin releases new update for all Forerunner smartwatches with fresh bug patch

Mykhailo Mudryk labelled ‘the most overrated player in the Premier League’
Sports6 days ago

Mykhailo Mudryk labelled ‘the most overrated player in the Premier League’

Kidnappers abduct journalist after publishing human rights violation story
News6 days ago

Four killed as gunmen attack Plateau mining site

Graeme Souness ‘feels sorry’ for Jude Bellingham after his role against Greece
Sports6 days ago

Graeme Souness ‘feels sorry’ for Jude Bellingham after his role against Greece

Reason behind Bukayo Saka's absence from tonight's England match against Finland
Sports5 days ago

Reason behind Bukayo Saka’s absence from tonight’s England match against Finland

Reps plan to establish Bola Tinubu University to teach Nigerian languages
News6 days ago

Reps plan to establish Bola Tinubu University to teach Nigerian languages

Sokoto provides the Army with 10 more patrol vehicles
News6 days ago

Sokoto provides the Army with 10 more patrol vehicles

The rival Android flagship appears to have outperformed the Samsung Galaxy S25 Ultra On Geekbench
Technology6 days ago

The rival Android flagship appears to have outperformed the Samsung Galaxy S25 Ultra On Geekbench

Oba Adedotun Gbadebo cautions Ogun booksellers on piracy
News2 days ago

Oba Adedotun Gbadebo cautions Ogun booksellers on piracy

London Tailor: How family called meeting to stop my fashion ambition
Entertainment6 days ago

London Tailor: How family called meeting to stop my fashion ambition

Primary schools to teach skills such as plumbing, hairstyling from 2025
News3 days ago

Primary schools to teach skills such as plumbing, hairstyling from 2025

A British boxer was arrested by airport security after smashing a fan's phone in a fit of rage
Sports2 days ago

A British boxer was arrested by airport security after smashing a fan’s phone in a fit of rage

Rivers LG chairman removes Wike’s name from council building
News5 days ago

Rivers LG chairman removes Wike’s name from council building

Tony Cascarino claims William Saliba is ‘at the level of a Real Madrid player’
Sports3 days ago

Tony Cascarino claims William Saliba is ‘at the level of a Real Madrid player’

BBNaija: I regret some things I did in Big Brother’s house — Ruthee
Entertainment5 days ago

BBNaija: I regret some things I did in Big Brother’s house — Ruthee

Hold VeryDarkMan responsible — Bobrisky to Falana, Falz
Entertainment2 days ago

Falana, Falz give Bobrisky 12-hour ultimatum to apologise, retract defamatory claims

Remove defamatory posts on Falana, Falz — Court orders VDM
Entertainment2 days ago

Remove defamatory posts on Falana, Falz — Court orders VDM

Davido and Darkoo collaborate on the thrilling new single "Right Now"
Entertainment5 days ago

Davido and Darkoo collaborate on the thrilling new single “Right Now”

EFCC
News2 days ago

Court stops EFCC from arresting ex-defence minister Batagarawa

Kogi seeks FG’s intervention as communities are devastated by flooding
News3 days ago

Kogi seeks FG’s intervention as communities are devastated by flooding

Man who cannot feed his family has no need to use his private parts on a woman — Kanayo O. Kanayo
Entertainment6 days ago

Kanayo O. Kanayo gives Gen Zs tips on how to get favour from older folks

Android 16 will offer a Terminal and complete Linux VM compatibility, including GPU acceleration
Technology4 days ago

Android 16 will offer a Terminal and complete Linux VM compatibility, including GPU acceleration

I can’t horrify people like I used to anymore — Alice Cooper
Entertainment5 days ago

I can’t horrify people like I used to anymore — Alice Cooper

APC youths demand justice and condemn Ogun councillorship candidate’s murder
News5 days ago

APC youths demand justice and condemn Ogun councillorship candidate’s murder

Mr Macaroni responds to the controversial video of children reenacting his skit
Entertainment2 days ago

Mr Macaroni responds to the controversial video of children reenacting his skit

Panic as two-storey building collapses in Lagos
News4 days ago

Panic as two-storey building collapses in Lagos

Matawalle slams Amaechi over protest call
News5 days ago

Matawalle slams Amaechi over protest call

Serious warning to Android users to stop downloading malicious apps
Technology3 days ago

Serious warning to Android users to stop downloading malicious apps

I regret not having baby mamas — Singer Skales
Entertainment2 days ago

I regret not having baby mamas — Singer Skales

ANE Billboard Hots