New issue
Advanced search Search tips

Issue 863634 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jul 14
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Domain level access UAC Vulnerability

Reported by csalve...@gmail.com, Jul 13

Issue description


VULNERABILITY DETAILS
In a domain enviorment behind a Fortigate firewall appliance. In a standard domain, a user recieves a Connect Wise link and connects with a HelpDesk technician to resolve an issue they are having. The helpdesk technician sends a command to elivate the UAC of the session in order to run admisitratrive tasks are uninstalling a program or updating something. After the technican disconnects Google Chrome keeps the elivated access of the technican that was connected and the user is now able to, through chrome, access sites that they would otherwise be restricted from due to web filter policies. This elivated access in the web browsers is also able to run HTTP/HTTPS processes via API"s to run scripts. 

VERSION
Chrome Version: 67.0.3396.99
Operating System: Tested on Windows 10 Ver: 1803

REPRODUCTION CASE
See Pic. 
I removed my System admin web policy and was getting blocked on other browsers, IE, Edge, Firefox but i was not getting block on Google Chrome. I was able to stream videos, install plugins and run web app's on sharepoint. In the background is the firewall showing that Youtube is being denied yet still running. We were notified of this because users were able to get to sites that they would otherwise be blocked after a technician had worked with them through a remote support session. On Monday we will be doing more testing on the implications of this as it is on our risk assessment now. 
 
Chrome Vulnerability.png
895 KB View Download
Status: WontFix (was: Unconfirmed)
This sounds like a problem with your firewall appliance rather than with Chrome, so you'll probably need to contact Fortigate. I'm not sure why this might be happening -- perhaps Chrome uses longer-lived connections than other browsers -- but if the appliance isn't properly closing connections from Chrome, that's something they'd have to fix on their end. Sorry we can't be of more help!
Thank you we will do more testing tomorrow (Monday) to see if keep-alive connections can be adjusted on the Fortigate appliance. 
Project Member

Comment 3 by sheriffbot@chromium.org, Oct 21

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment