[ << ALL_FEED ]

Not a Pwn2Own bug

More in General

Not a Pwn2Own bug 🙂

CVE-2024-43641: a CWE-190 type error allowed overflowing the reference count on a _CM_KEY_SECURITY instance. The vulnerable code was located in ntoskrnl.exe — in the CmpSetSecurityDescriptorInfo function (screenshot 1).

In order to reach the vulnerable code, it is necessary to open or create a registry key in transaction mode. This can be done via the RegCreateKeyTransacted function. Since there is no limit on the number of operations that can be recorded within a single transaction, we can successively call the NtSetSecurityObject function. And each such call will increment the reference count by 1.

In order for the vulnerability to “detonate,” it is necessary to wrap the reference count value around so that its value becomes less than the actual number of operations recorded within the transaction. If this condition is met, then after the transaction the _CM_KEY_SECURITY cell will be freed before the operations that need to be completed have finished, which will lead to use-after-free (screenshot 2).

The third screenshot shows part of the CmpDereferenceSecurityNode function responsible for decrementing the reference count and freeing _CM_KEY_SECURITY.

🩹 About the patch

The patch reworked how the Configuration Manager (CM) subsystem works with references to _CM_KEY_SECURITY, adding at least two new functions — CmpKeySecurityDecrementReferenceCount and CmpKeySecurityIncrementReferenceCount, which will now issue a bugcheck if the reference count becomes equal to zero or if after incrementing it is less than before (screenshot 4).

Fortunately, the vulnerability is hardly likely to be classifiable as exploitable, since overflowing the reference count by successively incrementing it by 1 would require a very long time, and the window within which we have the opportunity to “slip in” something is too small and uncontrollable.

#cve #escvr
@ptescalator

More from author_vr

More from author_vr

More in General