{"id":44183,"date":"2015-04-22T07:00:00","date_gmt":"2015-04-22T21:00:00","guid":{"rendered":"https:\/\/blogs.msdn.microsoft.com\/oldnewthing\/2015\/04\/22\/it-rather-involved-being-on-the-other-side-of-this-airtight-hatchway-invalid-parameters-from-one-security-level-crashing-code-at-the-same-security-level-yet-again\/"},"modified":"2019-03-13T12:14:56","modified_gmt":"2019-03-13T19:14:56","slug":"20150422-00","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/oldnewthing\/20150422-00\/?p=44183","title":{"rendered":"It rather involved being on the other side of this airtight hatchway: Invalid parameters from one security level crashing code at the same security level (yet again)"},"content":{"rendered":"<p>It&#8217;s the bogus vulnerability that keeps on giving. This time a security researcher found a horrible security flaw in <code>Sys&shy;Alloc&shy;String&shy;Len<\/code>: <\/p>\n<blockquote CLASS=\"q\">\n<p>The <code>Sys&shy;Alloc&shy;String&shy;Len<\/code> function is vulnerable to a denial-of-service attack. [Long description of reverse-engineering deleted.] <\/p>\n<p>The <code>Sys&shy;Alloc&shy;String&shy;Len<\/code> does not check the length parameter properly. If the provided length is larger than the actual length of the buffer, it may encounter an access violation when reading beyond the end of the buffer. Proof of concept: <\/p>\n<pre>\nSysAllocStringLen(L\"Example\", 0xFFFFFF);\n<\/pre>\n<p>Credit for this vulnerability should be given to XYZ Security Labs. Copyright &copy; XYZ Security Labs. All rights reserved. <\/p>\n<\/blockquote>\n<p>As with other issues of this type, there is no elevation. The attack code and the code that crashes are on the same side of the airtight hatchway. If your goal was to make the process crash, then instead of passing invalid parameters to the <code>Sys&shy;Alloc&shy;String&shy;Len<\/code> function, you can launch the denial of service attack much more easily: <\/p>\n<pre>\nint __cdecl main(int, char**)\n{\n    ExitProcess(0);\n}\n<\/pre>\n<p>Congratulations, you just launched a denial-of-service attack against yourself. <\/p>\n<p>In order to trigger an access violation in the <code>Sys&shy;Alloc&shy;String&shy;Len<\/code> function, you must already have had enough privilege to run code, which means that you already have enough privilege to terminate the application without needing the <code>Sys&shy;Alloc&shy;String&shy;Len<\/code> function. <\/p>\n<p>Once again, we have a case of <a HREF=\"http:\/\/blogs.msdn.com\/b\/oldnewthing\/archive\/2007\/08\/07\/4268706.aspx#4282521\">MS07-052: Code execution results in code execution<\/a>.&sup1; <\/p>\n<p><b>Earlier in the series<\/b>: <\/p>\n<ul>\n<li>    <a HREF=\"http:\/\/blogs.msdn.com\/b\/oldnewthing\/archive\/2014\/04\/02\/10512890.aspx\">    Episode 2<\/a>. \n<li>    <a HREF=\"http:\/\/blogs.msdn.com\/b\/oldnewthing\/archive\/2010\/12\/08\/10101773.aspx\">    Episode 1<\/a>. <\/ul>\n<p><b>Bonus bogus vulnerability report<\/b>: <\/p>\n<blockquote CLASS=\"q\"><p>The <code>Draw&shy;Text<\/code> function is vulnerability to a denial-of-service attack because it does not validate that the <code>lpchText<\/code> parameter is a valid pointer. If you pass <code>NULL<\/code> as the second parameter, the function crashes. We have found many functions in the system which are vulnerable to the same issue. <\/p><\/blockquote>\n<p>&sup1; Now, of course, if there were some way you could externally induce a program into passing invalid parameters to the <code>Sys&shy;Alloc&shy;String&shy;Length<\/code> function, then you&#8217;d be onto something. But even then, the vulnerability would be in the program that is passing the invalid parameters, not in the <code>Sys&shy;Alloc&shy;String&shy;Length<\/code> function itself. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>You never crossed the boundary.<\/p>\n","protected":false},"author":1069,"featured_media":111744,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[26],"class_list":["post-44183","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-oldnewthing","tag-other"],"acf":[],"blog_post_summary":"<p>You never crossed the boundary.<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/44183","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/users\/1069"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/comments?post=44183"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/44183\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/media\/111744"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/media?parent=44183"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/categories?post=44183"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/tags?post=44183"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}