04.04.2016 Views

A New CVE-2015-0057 Exploit Technology

asia-16-Wang-A-New-CVE-2015-0057-Exploit-Technology

asia-16-Wang-A-New-CVE-2015-0057-Exploit-Technology

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

64-bit <strong>Exploit</strong> Method<br />

The write control capability of the Misaligned tagPROPLIST object<br />

U-A-F tagPROPLIST<br />

cEntries && iFirstFree<br />

Zombie tagPROPLIST<br />

1<br />

cEntries && iFirstFree<br />

2<br />

tagWND<br />

3<br />

Misalignment<br />

tagWND.ppropList<br />

……<br />

4<br />

ThunkedMenuItemInfo Routine<br />

tagMENU<br />

tagMENU.cItems<br />

tagMENU.rgItems<br />

……<br />

Arbitrary Write<br />

6<br />

Arbitrary Read<br />

5

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!