[ << ALL_FEED ]

How we found the ITW exploit for CVE-2024-38178

More in General

🔦 How We Found the ITW Exploit for CVE-2024-38178

As part of our monthly review of freshly patched vulnerabilities, our team in ESC-VR pays close attention to vulnerabilities marked as exploited in the wild. Such vulnerabilities become our primary target, especially when no information about public exploits is available.

The vulnerability CVE-2024-38178 is a Type Confusion memory corruption (CWE-843). Simply put: a situation where a memory region occupied by an object of type A is interpreted by the code as an object of type B.

After analyzing the patch, we found that the changes were made to a function responsible for optimizing array operations, specifically the GlobOpt::OptArraySrc function. The fix added handling for a scenario where the optimizer fails to notice that a variable’s type can sometimes change at runtime.

If you follow Google ProjectZero‘s work as closely as we do, you’ve already guessed it 😉

The GlobOpt::OptArraySrc function had already appeared in an ITW exploit, specifically in the post describing CVE-2022-41128.

That post includes a PoC demonstrating the exploitation of CVE-2022–41128. Taking key strings from it, we searched public and private sources for recently uploaded files using the following substrings:

• 6E6577204F626A656374287B0D0A20
• 206E657720496E7433324172726179

We found only one file. It was uploaded from KR, and the exploit was likely used in attacks in that country, as indirectly indicated by information from the Microsoft bulletin.

Running the file on systems with and without the patch, we quickly realized this was exactly what we were looking for. Due to the high similarity to CVE-2022-41128, we believe this vulnerability was also discovered through fuzzing conducted using the PoC for CVE-2022-41128 and CVE-2021-34480.

The exploit creates a situation where the JIT compiler is convinced that variable X is of type js::TypedArray<int,0>, but in reality X holds value Y of type js::DynamicObj. The exploit then uses index access at positions 4, 11, and 12 to modify the internal fields of a js::JavaScriptNativeArray located in one of the properties of value Y. The modified fields store the array’s size.

As a result, the exploit enables out-of-bounds access to this array in order to obtain relative write and read primitives. Further description would take an indecent amount of space within a single post, so stay tuned and happy hunting 🙂

YARA rule (for the file):


rule exploit_CVE_2024_38178 {
      strings:
          $a = { 6E6577204F626A656374287B0D0A20 }
          $b = { 206E657720496E7433324172726179 } 
     condition:
           all of them
}

IoCs:


SHA256: 736092B71A9686FDE43D3C4ABD941A6774721B90B17D946C9D05AF19C84DF0A4

http://img[.]mobonad[.]com/images/20230912/43

#escvr #itw #jscript9 #reverse
@ptescalator

More from author_vr

More from author_vr

More in General