{"id":7163,"date":"2025-09-24T10:00:04","date_gmt":"2025-09-24T10:00:04","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/24\/hackers-exploit-werfaultsecure-exe-tool-to-steal-cached-passwords-from-lsass-on-windows-11-24h2\/"},"modified":"2025-09-24T10:00:04","modified_gmt":"2025-09-24T10:00:04","slug":"hackers-exploit-werfaultsecure-exe-tool-to-steal-cached-passwords-from-lsass-on-windows-11-24h2","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/24\/hackers-exploit-werfaultsecure-exe-tool-to-steal-cached-passwords-from-lsass-on-windows-11-24h2\/","title":{"rendered":"Hackers Exploit WerFaultSecure.exe Tool to Steal Cached Passwords From LSASS on Windows 11 24H2"},"content":{"rendered":"<p>    Hackers Exploit WerFaultSecure.exe Tool to Steal Cached Passwords From LSASS on Windows 11 24H2<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Threat actors are leveraging the legacy Windows error\u2010reporting utility WerFaultSecure.exe to extract the memory region of the Local Security Authority Subsystem Service (LSASS.EXE) and harvest cached credentials from fully patched <a href=\"https:\/\/cybersecuritynews.com\/windows-11-24h2-update-video\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows 11 24H2 systems<\/a>.\u00a0<\/p>\n<p>After gaining initial access to a host, adversaries frequently seek to dump LSASS memory to escalate privileges and move laterally across the network.\u00a0<\/p>\n<p>Modern Windows severely restricts direct memory access to <a href=\"https:\/\/cybersecuritynews.com\/exfiltrate-windows-secrets-and-credentials\/\" target=\"_blank\" rel=\"noreferrer noopener\">LSASS<\/a> by enforcing Protected Process Light (PPL), requiring kernel privilege or a peer PPL process for interaction.\u00a0<\/p>\n<p>Zero Salarium researchers have now demonstrated how to bypass these defenses by running a vulnerable WerFaultSecure.exe binary compiled for Windows 8.1 under Windows 11, thereby obtaining an unencrypted memory dump of LSASS.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-leveraging-werfaultsecure-exe-s-ppl-privilege\"><strong>Leveraging WerFaultSecure.exe\u2019s PPL Privilege<\/strong><\/h2>\n<p>WerFaultSecure.exe is part of the Windows Error Reporting (WER) framework and normally executes with the highest PPL label, WinTCB, to collect crash dumps from protected processes.\u00a0<\/p>\n<p>Its protected status allows it to access LSASS memory under the guise of a crash handler.\u00a0<\/p>\n<p>In Windows 8.1, a flaw existed whereby WerFaultSecure.exe could be imposed into writing crash dumps without applying its built\u2010in encryption routines, resulting in unencrypted dump files on disk.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img data-recalc-dims=\"1\" fetchpriority=\"high\" decoding=\"async\" width=\"640\" height=\"201\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-136.png?resize=640%2C201&#038;ssl=1\" alt=\"Exploiting WerFaultSecure.exe\" class=\"wp-image-127775\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-136.png 640w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-136-300x94.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-136-150x47.png 150w\" sizes=\"(max-width: 640px) 100vw, 640px\"><figcaption class=\"wp-element-caption\">Exploiting WerFaultSecure.exe<\/figcaption><\/figure>\n<\/div>\n<p>By copying the vulnerable WerFaultSecure.exe from Windows 8.1 onto a Windows 11 24H2 machine and launching it with PPL elevation, attackers can trick the tool into capturing LSASS memory and writing a raw dump.<\/p>\n<p>Zero Salarium <a href=\"https:\/\/www.zerosalarium.com\/2025\/09\/Dumping-LSASS-With-WER-On-Modern-Windows-11.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reports that<\/a> the exploit sequence involves running WerFaultSecure.exe with undocumented switches discovered through reverse engineering: \/h to invoke secure hidden crash mode, \/pid [pid] to target the LSASS process, \/tid [tid] to specify its main thread, and \/file [handle] to designate an unencrypted output handle.\u00a0<\/p>\n<p>The attacker uses a custom loader named WSASS to spawn WerFaultSecure.exe via the CreateProcessAsPPL API, inheriting handles for the crash dump and event objects.\u00a0<\/p>\n<p>WSASS waits for dump completion, then replaces the first four bytes of the generated file (from the PNG magic header) with the MDMP signature (0x4D,0x44,0x4D,0x50) so it masquerades as a benign image device and evades <a href=\"https:\/\/cybersecuritynews.com\/noneuclid-rat-bypassing-antivirus\/\" target=\"_blank\" rel=\"noreferrer noopener\">antivirus checks<\/a>.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"399\" height=\"281\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-137.png?resize=399%2C281&#038;ssl=1\" alt=\"Exploiting WerFaultSecure.exe\" class=\"wp-image-127776\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-137.png 399w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-137-300x211.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-137-100x70.png 100w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-137-150x106.png 150w\" sizes=\"(max-width: 399px) 100vw, 399px\"><figcaption class=\"wp-element-caption\">MDMP replaced<\/figcaption><\/figure>\n<\/div>\n<p>Finally, the loader resumes any suspended threads in LSASS by issuing minimal PROCESS_SUSPEND_RESUME rights to restore system stability.<\/p>\n<p>Once the attacker restores the MDMP header, the resulting minidump can be loaded into standard tools<span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">, such as pypykatz or Mimikatz, to extract\u00a0<a href=\"https:\/\/cybersecuritynews.com\/weaponized-zip-ntlm-hash-theft\/\" target=\"_blank\" rel=\"noopener\">NTLM hashes<\/a>\u00a0and plaintext credentials, facilitating<\/span> further lateral movement.\u00a0<\/p>\n<p>This technique underscores the importance of monitoring WerFaultSecure.exe binaries outside the System32 directory and validating PPL\u2010protected process invocations to detect anomalous behavior early.<\/p>\n<p>This exploit demonstrates how backward compatibility in Windows can be leveraged against modern defenses, highlighting the need for defenders to monitor both file locations and invocation contexts of error-reporting tools.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/windows-11-cached-passwords\/\">Hackers Exploit WerFaultSecure.exe Tool to Steal Cached Passwords From LSASS on Windows 11 24H2<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Florence Nightingale<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/windows-11-cached-passwords\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Exploit WerFaultSecure.exe Tool to Steal Cached Passwords From LSASS on Windows 11 24H2 Threat actors are leveraging the legacy Windows error\u2010reporting utility WerFaultSecure.exe to extract the memory region of the Local Security Authority Subsystem Service (LSASS.EXE) and harvest cached credentials from fully patched Windows 11 24H2 systems.\u00a0 After gaining initial access to a host, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,395],"tags":[130],"class_list":["post-7163","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-windows","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7163"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7163"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7163\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7163"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7163"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7163"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}