New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.
Starred by 2 users
Status: Fixed
Owner:
Email to this user bounced
Closed: Jun 2015
Cc:



Sign in to add a comment
Windows kernel: use-after-free in bitmap handling
Reported by cevans@google.com, Mar 20 2015 Back to list
Credit is to "Nils Sommer of bytegeist, working with Google Project Zero".

Platform: Win7 32-bit.
trigger.cpp should fire the issue, with two caveats:
- PoC will NOT work if compiled as a debug build.
- PoC will trigger the condition every time but the subsequent corruption might not cause a crash every time. It may be necessary to run the PoC multiple times.

debug.txt is a sample crash log.

Analysis from Nils:

---
Using the series of calls we are able to free the bitmap object, a reference to this object still exists in the trigger process after killing the first notepad process.

At this time we are able to replace the freed object in memory. We are not able to reuse this object through the original handle, however another free is triggered when quitting the trigger process, which will decrement the reference counter on the freed or replaced object, either modifying heap metadata or freeing the object which was allocated in the place of the original bitmap object.
---

This bug is subject to a 90 day disclosure deadline. If 90 days elapse
without a broadly available patch, then the bug report will automatically
become visible to the public.

 
debug.txt
4.3 KB View Download
trigger.cpp
1.2 KB Download
Comment 1 by cevans@google.com, Mar 20 2015
Cc: nils.som...@gmail.com
cc: Nils
Comment 2 by cevans@google.com, Mar 20 2015
Labels: Id-21788
Comment 3 by cevans@google.com, Mar 26 2015
Attaching better PoC.
bug293.cpp
2.3 KB Download
Comment 4 by cevans@google.com, Mar 26 2015
Labels: -Reported-2015-Mar-19 Reported-2015-Mar-26
Comment 5 by cevans@google.com, Jun 4 2015
Labels: CVE-2015-1722
Comment 6 by cevans@google.com, Jun 4 2015
Same root cause as https://code.google.com/p/google-security-research/issues/detail?id=311, according to Microsoft. CVE shared.
Project Member Comment 8 by hawkes@google.com, Sep 21 2015
Labels: -Restrict-View-Commit
Sign in to add a comment