{"id":8883,"date":"2011-12-15T07:00:00","date_gmt":"2011-12-15T07:00:00","guid":{"rendered":"https:\/\/blogs.msdn.microsoft.com\/oldnewthing\/2011\/12\/15\/not-even-making-it-to-the-airtight-hatchway-execution-even-before-you-get-there\/"},"modified":"2011-12-15T07:00:00","modified_gmt":"2011-12-15T07:00:00","slug":"not-even-making-it-to-the-airtight-hatchway-execution-even-before-you-get-there","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/oldnewthing\/20111215-00\/?p=8883\/","title":{"rendered":"Not even making it to the airtight hatchway: Execution even before you get there"},"content":{"rendered":"<p>\nToday&#8217;s dubious security vulnerability comes from somebody who\nreported that the <code>Load&shy;Keyboard&shy;Layout<\/code> function\nhad a security vulnerability which could lead to arbitrary code\nexecution.\nThis is a serious issue, but reading the report made us wonder\nif something was missing.\n<\/p>\n<pre>\n\/\/ sample program to illustrate the vulnerability.\n#include &lt;windows.h&gt;\n#include &lt;stdio.h&gt;\n#include &lt;stdlib.h&gt;\nint __cdecl main(int argc, char **argv)\n{\n LoadKeyboardLayout(\"whatever\", system(\"notepad.exe\"));\n return 0;\n}\n<\/pre>\n<p>\nAccording to the report, this sample program illustrates that\nthe <code>Load&shy;Keyboard&shy;Layout<\/code> function\nwill execute whatever you pass as its second parameter.\nIn this case, the program chose to launch Notepad,\nbut obviously an attacker could change the code to something\nmore dangerous.\n<\/p>\n<p>\nWe had trouble trying to figure out what the person was trying to say.\nAfter all, it&#8217;s not the\n<code>Load&shy;Keyboard&shy;Layout<\/code> function\nthat is executing the second parameter.\nIt&#8217;s the sample program that&#8217;s doing it,\nand using the return value as the second parameter to the\n<code>Load&shy;Keyboard&shy;Layout<\/code> function.\nI mean, you can use this &#8220;technique&#8221; on the function\n<\/p>\n<pre>\nvoid donothing(int i) { }\n<\/pre>\n<p>\nto demonstrate that the <code>donothing<\/code> function has\nthe same &#8220;vulnerability&#8221;:\n<\/p>\n<pre>\ndonothing(system(\"notepad.exe\"));\n<\/pre>\n<p>\nLogically, the compiler decomposes the call to\n<code>Load&shy;Keyboard&shy;Layout<\/code> function as\n<\/p>\n<pre>\n auto param2 = system(\"notepad.exe\");\n LoadKeyboardLayout(\"whatever\", param2);\n<\/pre>\n<p>\nand now it&#8217;s clear that it&#8217;s not the\n<code>Load&shy;Keyboard&shy;Layout<\/code> function which is\nexecuting its second parameter; it&#8217;s <i>you<\/i>.\n<\/p>\n<p>\nThis is like taking a printed picture of your friend into a secured area,\nthen saying,\n&#8220;See, I have a picture!\nYour security failed to stop me from taking a picture!&#8221;\nThat picture was taken outside the secured area.\nWhat you have is not a security vulnerability because the picture\nwas taken on the other side of the airtight hatchway.\n<\/p>\n<p>\nBefore contacting the submitter, we want to be sure that we weren&#8217;t\nmissing something,\nbut after looking at it from every angle, we still couldn&#8217;t see what\nthe issue was.\nWe ran the alleged exploit under the kernel debugger and traced\nthrough the entire\n<code>Load&shy;Keyboard&shy;Layout<\/code> function (both the user-mode\npart and the kernel-mode part)\nto confirm that the function never launched Notepad on its own.\nWe repeated the investigation on all service packs on all\nversions of Windows still under support (and even some that are\nno longer supported).\nStill nothing.\n<\/p>\n<p>\nStumped, we contacted the submitter.\n&#8220;From what we can tell, the call to <code>system<\/code> takes place\nbefore you call the\n<code>Load&shy;Keyboard&shy;Layout<\/code> function.\nCan you elaborate on how this constitutes a vulnerability in the\n<code>Load&shy;Keyboard&shy;Layout<\/code> function?&#8221;\n<\/p>\n<p>\nApparently, the submitter didn&#8217;t quite understand what we were after,\nbecause the response was just more of the same.\n&#8220;I have discovered that the Visual Basic\n<code>MsgBox<\/code> function\nhas a similar vulnerability:\n<\/p>\n<pre>\nModule Program\nSub Main()\n MsgBox(System.Diagnostics.Process.Start(\"notepad.exe\").ToString())\nEnd Sub\nEnd Module\n<\/pre>\n<p>\nThe <code>MsgBox<\/code> method will execute whatever you\npass as its parameter,\nas long as the result is a string.\n(You can even pass something that isn&#8217;t a string, but it&#8217;ll throw\nan exception after executing it.)\nThe documentation for <code>MsgBox<\/code> clearly states that\nthe function displays a message box with the specified text.\nIt should therefore display a string and not execute a program!&#8221;\n<\/p>\n<p>\nAt this point,\nwe had to give up.\nWe couldn&#8217;t figure out what the person was trying to report,\nand our attempt to obtain a clarification was met with another version\nof what appeared to be the same nonsense.\nAs I recall, this entire investigation took five days to complete,\nplus another day or two to complete the necessary paperwork.\nEach year,\n<a HREF=\"http:\/\/www.technologyreview.com\/blog\/editors\/23100\/\">\n200,000 vulnerability reports are received<\/a>,\nand each one is taken seriously,\n<a HREF=\"http:\/\/blogs.msdn.com\/b\/oldnewthing\/archive\/2008\/03\/14\/8080140.aspx\">\neven the bogus-looking ones<\/a>,\nbecause there might be a real issue hiding behind a bogus-looking report.\nSort of how the people in the emergency communication center\nhave to follow through on every\n<a HREF=\"http:\/\/en.wikipedia.org\/wiki\/Emergency_telephone_number\">\n911<\/a>\ncall, even the ones that they strongly suspect are bogus,\nand even though dealing with the suspected-bogus ones\n<a HREF=\"http:\/\/www2.newsadvance.com\/lna\/news\/local\/article\/911_hang-ups_mean_backups_for_dispatchers\/12264\/\">\nslows down the overall response time for everyone<\/a>.\n<\/p>\n<p>\nThese sort-of-but-not-quite reports are among the most frustrating.\nThere&#8217;s enough sense in the report that it makes you wonder if there&#8217;s\na real vulnerability lurking in there, but which remains elusive because\nthe author is unable (perhaps due to a language barrier)\nto articulate it clearly.\nThey live in the shadowy ground between the reports that are\nclearly crackpot\nand the reports which are clear enough that you can evaluate them\nwith confidence.\nThese middle-ground reports are just plausible enough to be dangerous.\nAs a result, you close them out with trepidation,\nbecause there&#8217;s the risk\nthat there really is something there, but you just aren&#8217;t seeing it.\nThen you have nightmares that the finder has taken the report public,\nand the vulnerability report you rejected as bogus is now\nheadline news all over the technology press.\n(Or worse, exploits start showing up taking advantage of the vulnerability\nyou rejected as bogus two months ago.)\n<\/p>\n<p>\n<b>Update<\/b>:\nSure, this looks like something you can reject out of hand.\nBut maybe there&#8217;s something there after all.\nPerhaps\nthe <code>system<\/code> call somehow\n&#8220;primed the pump&#8221; and left the system in just the right state\nso that an uninitialized variable resulted in Notepad being\nlaunched a second time or editing its token to have higher\nprivileges.\nIn that case,\nyou rejected a genuine security vulnerability,\nand then when hackers start using it to build a botnet,\nsomebody will go back into the vulnerability investigation logs,\nand the only entry will be\n&#8220;Rejected without investigation by Bob.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today&#8217;s dubious security vulnerability comes from somebody who reported that the Load&shy;Keyboard&shy;Layout function had a security vulnerability which could lead to arbitrary code execution. This is a serious issue, but reading the report made us wonder if something was missing. \/\/ sample program to illustrate the vulnerability. #include &lt;windows.h&gt; #include &lt;stdio.h&gt; #include &lt;stdlib.h&gt; int __cdecl [&hellip;]<\/p>\n","protected":false},"author":1069,"featured_media":111744,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[26],"class_list":["post-8883","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-oldnewthing","tag-other"],"acf":[],"blog_post_summary":"<p>Today&#8217;s dubious security vulnerability comes from somebody who reported that the Load&shy;Keyboard&shy;Layout function had a security vulnerability which could lead to arbitrary code execution. This is a serious issue, but reading the report made us wonder if something was missing. \/\/ sample program to illustrate the vulnerability. #include &lt;windows.h&gt; #include &lt;stdio.h&gt; #include &lt;stdlib.h&gt; int __cdecl [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/8883","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/users\/1069"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/comments?post=8883"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/8883\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/media\/111744"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/media?parent=8883"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/categories?post=8883"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/tags?post=8883"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}