How we found the ITW exploit for CVE-2024-38178

More in General
- Out-of-bounds write in ntfs!PageUpdateAnalysis
A heap buffer overflow vulnerability exists in the ntfs!PageUpdateAnalysis function of the Microsoft Windows NTFS driver.…
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- VMkatz: a hidden threat to virtual infrastructure 🫣
In 2026, a tool called VMkatz was published. In terms of functionality, it resembles the widely…
- ⚠️ Enabled Wi-Fi debugging — got Mamont
⚠️ Turned on Wi-Fi debugging — got Mamont In early May, a vulnerability CVE-2026-0073 was discovered…
🔦 How We Found the ITW Exploit for CVE-2024-38178
As part of our monthly review of freshly patched vulnerabilities, our team in ESC-VR pays close attention to vulnerabilities marked as exploited in the wild. Such vulnerabilities become our primary target, especially when no information about public exploits is available.
The vulnerability CVE-2024-38178 is a Type Confusion memory corruption (CWE-843). Simply put: a situation where a memory region occupied by an object of type A is interpreted by the code as an object of type B.
After analyzing the patch, we found that the changes were made to a function responsible for optimizing array operations, specifically the GlobOpt::OptArraySrc function. The fix added handling for a scenario where the optimizer fails to notice that a variable’s type can sometimes change at runtime.
If you follow Google ProjectZero‘s work as closely as we do, you’ve already guessed it 😉
The GlobOpt::OptArraySrc function had already appeared in an ITW exploit, specifically in the post describing CVE-2022-41128.
That post includes a PoC demonstrating the exploitation of CVE-2022–41128. Taking key strings from it, we searched public and private sources for recently uploaded files using the following substrings:
• 6E6577204F626A656374287B0D0A20
• 206E657720496E7433324172726179
We found only one file. It was uploaded from KR, and the exploit was likely used in attacks in that country, as indirectly indicated by information from the Microsoft bulletin.
Running the file on systems with and without the patch, we quickly realized this was exactly what we were looking for. Due to the high similarity to CVE-2022-41128, we believe this vulnerability was also discovered through fuzzing conducted using the PoC for CVE-2022-41128 and CVE-2021-34480.
The exploit creates a situation where the JIT compiler is convinced that variable X is of type js::TypedArray<int,0>, but in reality X holds value Y of type js::DynamicObj. The exploit then uses index access at positions 4, 11, and 12 to modify the internal fields of a js::JavaScriptNativeArray located in one of the properties of value Y. The modified fields store the array’s size.
As a result, the exploit enables out-of-bounds access to this array in order to obtain relative write and read primitives. Further description would take an indecent amount of space within a single post, so stay tuned and happy hunting 🙂
YARA rule (for the file):
rule exploit_CVE_2024_38178 {
strings:
$a = { 6E6577204F626A656374287B0D0A20 }
$b = { 206E657720496E7433324172726179 }
condition:
all of them
}
IoCs:
SHA256: 736092B71A9686FDE43D3C4ABD941A6774721B90B17D946C9D05AF19C84DF0A4
http://img[.]mobonad[.]com/images/20230912/43
#escvr #itw #jscript9 #reverse
@ptescalator
More in General
- Out-of-bounds write in ntfs!PageUpdateAnalysis
A heap buffer overflow vulnerability exists in the ntfs!PageUpdateAnalysis function of the Microsoft Windows NTFS driver.…
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- VMkatz: a hidden threat to virtual infrastructure 🫣
In 2026, a tool called VMkatz was published. In terms of functionality, it resembles the widely…
- ⚠️ Enabled Wi-Fi debugging — got Mamont
⚠️ Turned on Wi-Fi debugging — got Mamont In early May, a vulnerability CVE-2026-0073 was discovered…






