• Project Zero : Windows: splWOW64 Elevation of Privilege

    Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » Project Zero : Windows: splWOW64 Elevation of Privilege

    Author
    Topic
    #2322504

    Windows: splWOW64 Elevation of Privilege
    Platform: Windows 10 2004 (19041.508)
    Class: Elevation of Privilege

    Summary: CVE-2020-0986, which was exploited in the wild[1] was not fixed. The vulnerability still exists, just the exploitation method had to change.

    A low integrity process can send LPC messages to splwow64.exe (Medium integrity) and gain a write-what-where primitive in splwow64’s memory space. The attacker controls the destination, the contents that are copied, and the number of bytes copied through a memcpy call. The offset for the destination pointer calculation is only constrained to be:
    Offset <= 0x7FFFFFFF
    Offset + perceived size of structure <= 0x7FFFFFFF

    Splwow64 passes the LPC message to GdiPrinterThunk. The vulnerable memcpy is in message 0x6D. …

    Viewing 2 reply threads
    Author
    Replies
    • #2322529

      There are hints in that thread on the Project Zero page that you link to that MS may very well have a patch next month on Patch Tuesday. Time will tell, of course.

      The bug was disclosed because MS couldn’t meet Project Zero’s normal time line nor could they meet an extended time line for patching the bug.

      From what’s mentioned on the Project Zero page and in an article on Bleeping Computer about the bug, sounds like MS took the easy way out of the bug back in May/June and left themselves open hoping nobody would notice. OOPS!!

      • This reply was modified 4 years, 5 months ago by Bob99. Reason: typo correction
    • #2322603

      As this seems to require software running on the local machine it is easy to mitigate – don’t run dodgy software on your machine.

      cheers, Paul

      1 user thanked author for this post.
    • #2322659

       
      From CVE timeline:

      2020-10-27 Microsoft assigns CVE-2020-17008 for this issue, noting that while the fix was planned for November, that has slipped to December.
      2020-12-03 Microsoft advises that due to issues identified in testing, the fix will now slip to January 2021.
      2020-12-08 Meeting between MSRC and Project Zero leadership to determine details and discuss next steps. The 14-day grace period is unavailable as Microsoft do not plan to patch this issue before Jan 6 (next patch Tuesday is Jan 12).

    Viewing 2 reply threads
    Reply To: Project Zero : Windows: splWOW64 Elevation of Privilege

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: