04.04.2016 Views

A New CVE-2015-0057 Exploit Technology

asia-16-Wang-A-New-CVE-2015-0057-Exploit-Technology

asia-16-Wang-A-New-CVE-2015-0057-Exploit-Technology

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The Old-school Kernel Attack Surface<br />

<strong>Exploit</strong> Code<br />

3<br />

DestroyWindow(ScrollHandle)<br />

5<br />

Allocate Object<br />

2<br />

Ring-3<br />

User Mode Callback<br />

Callback Return<br />

Ring-0<br />

4<br />

RtlpFreeHeap<br />

Win32k.sys<br />

Desktop Heap<br />

xxxEnableWndSBArrows<br />

1<br />

tagSBINFO<br />

Array . Size<br />

6<br />

7<br />

xxxEnableWndSBArrows<br />

Use-After-Free<br />

chunk #02<br />

chunk #02<br />

Array . Size<br />

chunk #03<br />

chunk #03 chunk #03<br />

8 Arbitrary Memory Write<br />

…….. …….. ……..

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!