Windows 0-day exploit used in Operation WizardOpium
securelist.com
securelist.com
https://www.bleepingcomputer.com/news/security/windows-chrom...
"Last month, Kaspersky revealed that they discovered a zero-day Google Chrome vulnerability that was actively being used in online attacks called Operation WizardOpium.
The attackers had hacked a Korean-language news site and injected a JavaScript tag into the site that would execute malicious scripts in the visitor's browser."
> At the same time, it tries to leak a few kernel pointers using well-known techniques to leak kernel memory addresses (gSharedInfo, PEB’s GdiSharedHandleTable).
Wait, Windows exports kernel address to userspace?!
Dont know about these particular calls. But info leaks where a kernel address is leaked are apparently quite common. They're usually fixed when found. But this is the reason OpenBSD relinks the kernel every boot in a random order. [0]
Its's too easy to leak a pointer and invalidate KASLR, because now you can calculate the KASLR offset.
The 'well known' part does seem a bit weird though.
[0] https://security.stackexchange.com/questions/163565/openbsd-...
Edit: https://github.com/sam-b/windows_kernel_address_leaks/blob/m...
Seems windows patches them too, sometimes. Checking the rest of the repo they don't seem to care much though.
GDI objects make these even more complicated because they were originally designed to be fully userspace, but were moved to kernel for performance reasons back in the NT 4 days. "Security" meant something quite different back in the early 90s when this was done.
It seems like it's the case here where normal, unprivileged code can just read out kernel pointers. I don't know of any other well-used platform that makes it this easy.
FWIW most data in GDI objects is non critical. It doesn’t really matter if a process corrupts a brush to be red instead of green. So some GDI data is allowed to be user space accessible.
The mixed ownership is indeed a design "flaw" but it comes from the fact that GDI was initially 100% userspace (in win NT). FWIW GDI has been superseded by D2D which has a better design.
You are correct GDI as an interface predates NT and protected mode in general, but the codebase used in NT is a different implementation.
First link in the article. It's a codename Kaspersky is using for this attack campaign.
Life is no longer distinct from a William Gibson novel.
It's how computer programs talk! :)
Bah.
Published 13 days ago. You can subscribe for securuty bulletin.
I imagine MS/Chrome will treat this as an emergency out-of-cycle patch which I don't think many people would disagree with :)