[ << ALL_FEED ]

CVE-2024-43629 Vulnerability Details

More in Windows

😏 Exclusively for Escalator, the ESC-VR team shares details about the vulnerability (CVE-2024-43629) that we found in the Desktop Window Manager component, allowing privilege escalation to system level.

The vulnerability was located in the dwmcore.dll library in the CPrimitiveGroupDrawListBrush::IsColorConversionRequired function (screenshot 1). When the CSurfaceBrush and CPrimitiveGroup classes were used together, it allowed reaching code that calculates the position of a CDrawListBitmap class instance in the drawListBitmap_Vec array, which in turn is located in an instance of the CPrimitiveGroupDrawListGenerator class.

With a certain combination of properties of the CSurfaceBrush and CPrimitiveGroup instances, a situation could arise in which the drawListBitmap_Vec pointer would be equal to zero and all calculations would be reduced to working only with the index, and its value would be fully controlled by the attacker and would have the size DWORD. This way, it would be possible to hijack a pointer to a CDrawListBitmap object (screenshot 2).

#escvr #win #cve
@ptescalator

More from author_vr

More from author_vr

More in Windows