what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Microsoft Wireless Desktop 2000 Insufficent Protection

Microsoft Wireless Desktop 2000 Insufficent Protection
Posted Oct 10, 2016
Authored by Matthias Deeg, Gerhard Klostermeier | Site syss.de

Microsoft Wireless Desktop 2000 version A suffers from insufficient protection of code (firmware) and data (cryptographic key).

tags | advisory
SHA-256 | a2e84bef4f1b103936ce31df00ad89196bd85c85162d189f4577c1a150082ee0

Microsoft Wireless Desktop 2000 Insufficent Protection

Change Mirror Download
Hash: SHA512

Advisory ID: SYSS-2016-033
Product: Microsoft Wireless Desktop 2000
Manufacturer: Microsoft
Affected Version(s): Ver. A
Tested Version(s): Ver. A
Vulnerability Type: Insufficient Protection of Code (Firmware) and
Data (Cryptographic Key)
Risk Level: Medium
Solution Status: Open
Manufacturer Notification: 2016-04-22
Solution Date: -
Public Disclosure: 2016-10-05
CVE Reference: Not yet assigned
Authors of Advisory: Gerhard Klostermeier and Matthias Deeg (SySS GmbH)



Microsoft Wireless Desktop 2000 is a wireless desktop set consisting of
a mouse and a keyboard.

The manufacturer describes the product as follows (see [1]):

"This keyboard features Advanced Encryption Standard (AES) technology,
which is designed to help protect your information by encrypting your
keystrokes. Each keyboard is permanently paired with its receiver at
the factory - no key information is ever shared over the air."

Due to the insufficient protection of the flash memory of the keyboard
and of the USB dongle, an attacker with physical access has read and
write access to the firmware and the used cryptographic key.


Vulnerability Details:

The SySS GmbH found out that the embedded flash memory of the wireless
keyboard Microsoft Wireless Desktop 2000 and of the corresponding USB
dongle can be read and written via the SPI interface of the used
transceivers with an embedded microcontroller nRF24LE1H (keyboard) and
nRF24LU1+ (USB dongle) as the flash memory is not protected by the
offered read back protection feature (RDISMB - Read DISable Main Block).

Thus, an attacker with physical access to the keyboard or the USB
dongle can simply read and write the SPI-addressable code and data
flash memory. Due to the use of nRF24 transceiver versions with one-time
programmable memory, write access is limited in such a way that a set
1 bit can be changed to a 0 bit but not vice versa.

The AES cryptographic key used by the Microsoft Wireless Desktop 2000
keyboard and the corresponding USB dongle is for both devices accessible
via the SPI interface.

By having read and write access to the code and data flash memory, an
attacker can either extract the cryptographic key, for instance to
perform further attacks against the wireless communication, or modify
the firmware or the cryptographic key in a limited way due to the
used one-time programmable memory.


Proof of Concept (PoC):

The SySS GmbH could successfully read the contents of the code and data
flash memory of the Microsoft Wireless Desktop 2000 keyboard and of the
USB dongle using the hardware tool Bus Pirate [3] in combination with
the software tool nrfprog [4].



The SySS GmbH is not aware of a solution for this reported security

For further information please contact the manufacturer.


Disclosure Timeline:

2016-04-22: Vulnerability reported to manufacturer
2016-04-23: Manufacturer acknowledges e-mail with SySS security advisory
2016-06-06: E-mail to manufacturer according current status
2016-06-27: Another e-mail to manufacturer according current status
2016-06-27: E-mail from manufacturer requesting further information
2016-06-28: Provided further information and PoC software tool
2016-07-07: E-mail from manufacturer with further information and
question about intended disclosure
2016-07-08: E-mail to manufacturer concerning the planned responsible
2016-08-04: E-mail from manufacturer concerning limitations of actual
2016-10-05: Public release of the security advisory



[1] Product website for Microsoft Wireless Desktop 2000
[2] Website of Bus Pirate hardware tool
[3] nrfprog Github repository
[4] SySS Security Advisory SYSS-2016-033
[5] SySS Responsible Disclosure Policy



This security vulnerability was found by Gerhard Klostermeier and
Matthias Deeg of the SySS GmbH.

E-Mail: gerhard.klostermeier (at) syss.de
Public Key: https://www.syss.de/fileadmin/dokumente/PGPKeys/Gerhard_Klostermeier.asc
Key fingerprint = 8A9E 75CC D510 4FF6 8DB5 CC30 3802 3AAB 573E B2E7

E-Mail: matthias.deeg (at) syss.de
Public Key: https://www.syss.de/fileadmin/dokumente/Materialien/PGPKeys/Matthias_Deeg.asc
Key fingerprint = D1F0 A035 F06C E675 CDB9 0514 D9A4 BF6A 34AD 4DAB



The information provided in this security advisory is provided "as is"
and without warranty of any kind. Details of this security advisory may
be updated in order to provide as accurate information as possible. The
latest version of this security advisory is available on the SySS Web



Creative Commons - Attribution (by) - Version 3.0
URL: http://creativecommons.org/licenses/by/3.0/deed.en


Login or Register to add favorites

File Archive:

August 2022

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    20 Files
  • 2
    Aug 2nd
    4 Files
  • 3
    Aug 3rd
    6 Files
  • 4
    Aug 4th
    55 Files
  • 5
    Aug 5th
    16 Files
  • 6
    Aug 6th
    0 Files
  • 7
    Aug 7th
    0 Files
  • 8
    Aug 8th
    13 Files
  • 9
    Aug 9th
    13 Files
  • 10
    Aug 10th
    34 Files
  • 11
    Aug 11th
    16 Files
  • 12
    Aug 12th
    5 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    25 Files
  • 16
    Aug 16th
    3 Files
  • 17
    Aug 17th
    6 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags


packet storm

© 2022 Packet Storm. All rights reserved.

Hosting By