CVE-2012-1535 Adobe Flash Player Integer Overflow Vulnerability Analysis



Similar documents
The Leader in Cloud Security SECURITY ADVISORY

Windows XP SP3 Registry Handling Buffer Overflow

Heap-based Buffer Overflow Vulnerability in Adobe Flash Player

Abysssec Research. 1) Advisory information. 2) Vulnerable version

Bypassing Browser Memory Protections in Windows Vista

CORE SECURITY. Exploiting Adobe Flash Player in the era of Control Flow Guard. Francisco Falcon Black Hat Europe 2015 November 12-13, 2015

AJAX Storage: A Look at Flash Cookies and Internet Explorer Persistence

RIA SECURITY TECHNOLOGY

New Tool for Discovering Flash Player 0-day Attacks in the. Wild from Various Channels

Defense in Depth: Protecting Against Zero-Day Attacks

Hotpatching and the Rise of Third-Party Patches

ERNW Newsletter 51 / September 2015

風 水. Heap Feng Shui in JavaScript. Alexander Sotirov.

Bypassing Memory Protections: The Future of Exploitation

Adobe Flash Player and Adobe AIR security

The Prevalence of Flash Vulnerabilities on the Web

Firefox, Opera, Safari for Windows BMP file handling information leak. September Discovered by: Mateusz j00ru Jurczyk, Hispasec Labs

Exploiting nginx chunked overflow bug, the undisclosed attack vector

Will Dormann: Sure. Fuzz testing is a way of testing an application in a way that you want to actually break the program.

Application-Specific Attacks: Leveraging the ActionScript Virtual Machine

Custom Penetration Testing

Where s the FEEB? The Effectiveness of Instruction Set Randomization

Off-by-One exploitation tutorial

Integrated Network Vulnerability Scanning & Penetration Testing SAINTcorporation.com

Windows Remote Access

Enterprise Mobility Report 06/2015. Creation date: Vlastimil Turzík

Adobe Systems Incorporated

CS412/CS413. Introduction to Compilers Tim Teitelbaum. Lecture 20: Stack Frames 7 March 08

Attacking Obfuscated Code with IDA Pro. Chris Eagle

DEFENSE THROUGHOUT THE VULNERABILITY LIFE CYCLE WITH ALERT LOGIC THREAT AND LOG MANAGER

Intrusion Defense Firewall

Stack Overflows. Mitchell Adair

New Tool for Discovering Flash Player 0-day Attacks in the Wild from Various

Using Impatica for Power Point

Transport Layer Protocols

Stitching the Gadgets On the Ineffectiveness of Coarse-Grained Control-Flow Integrity Protection

Introduction. Figure 1 Schema of DarunGrim2

Web Design Specialist

The purpose of this report is to educate our prospective clients about capabilities of Hackers Locked.

Software Vulnerability Exploitation Trends. Exploring the impact of software mitigations on patterns of vulnerability exploitation

ASSEMBLY PROGRAMMING ON A VIRTUAL COMPUTER

PROBLEMS (Cap. 4 - Istruzioni macchina)

CORPORATE AV / EPP COMPARATIVE ANALYSIS

MWR InfoSecurity Advisory. Interwoven Worksite ActiveX Control Remote Code Execution. 10 th March Contents

Format string exploitation on windows Using Immunity Debugger / Python. By Abysssec Inc

A Link Layer Discovery Protocol Fuzzer

The Sandbox Roulette: are you ready to gamble? Rafal Wojtczuk Rahul Kashyap

Sandy. The Malicious Exploit Analysis. Static Analysis and Dynamic exploit analysis. Garage4Hackers

Advanced Endpoint Protection Overview

Install this update to increase the performance of web sites that use Ajax. After you install this item, you may have to restart your computer.

Absolute Backdoor Revisited. Vitaliy Kamlyuk, Kaspersky Lab Sergey Belov, Kaspersky Lab Anibal Sacco, Cubica Labs

Sandbox Roulette: Are you ready for the gamble?

WHITE PAPER. FortiWeb and the OWASP Top 10 Mitigating the most dangerous application security threats

Thin Client Virus Vulnerability Analysis HP Compaq t5000 Thin Clients

Chapter 6: Project Planning & Production

Secure in 2010? Broken in 2011!

Microsoft Migrating to PowerPoint 2010 from PowerPoint 2003

Eugene Tsyrklevich. Ozone HIPS: Unbreakable Windows

Exception and Interrupt Handling in ARM

Image Based Spam: White Paper

White Paper. No Signature Required: The Power of Emulation in Preventing Malware

Return-oriented programming without returns

ASL IT SECURITY XTREME XPLOIT DEVELOPMENT

How To Hack The Steam Voip On Pc Orchesterian Moonstone 2.5 (Windows) On Pc/Robert Kruber (Windows 2) On Linux (Windows 3.5) On A Pc

============================================================= =============================================================

Bypassing Windows Hardware-enforced Data Execution Prevention

XI'AN NOVASTAR TECH CO., LTD

Making the difference between read to output, and read to copy GOING BEYOND BASIC FILE AUDITING FOR DATA PROTECTION

Secure Web Application Coding Team Introductory Meeting December 1, :00 2:00PM Bits & Pieces Room, Sansom West Room 306 Agenda

What is Web Security? Motivation

Shane Hartman CISSP, GCIA, GREM Suncoast Security Society

CHAPTER 7: The CPU and Memory

Background. How much does EMET cost? What is the license fee? EMET is freely available from Microsoft without material cost.

winhex Disk Editor, RAM Editor PRESENTED BY: OMAR ZYADAT and LOAI HATTAR

Develop Computer Animation

Recommended Practice Case Study: Cross-Site Scripting. February 2007

WINDOWS UPDATES AND MAJOR BUILDS

Using Windows Movie Maker to Create Movies

Basics of Accessible Design

Reviewer s Guide. Morpheus Photo Animation Suite. Screenshots. Tutorial. Included in the Reviewer s Guide:

CDM Vulnerability Management (VUL) Capability

SQL Injection 2.0: Bigger, Badder, Faster and More Dangerous Than Ever. Dana Tamir, Product Marketing Manager, Imperva

INDUSTRIAL CONTROL SYSTEMS CYBER SECURITY DEMONSTRATION

Coverity White Paper. Reduce Your Costs: Eliminate Critical Security Vulnerabilities with Development Testing

DRIVE-BY DOWNLOAD WHAT IS DRIVE-BY DOWNLOAD? A Typical Attack Scenario

The AVR Microcontroller and C Compiler Co-Design Dr. Gaute Myklebust ATMEL Corporation ATMEL Development Center, Trondheim, Norway

MWR InfoSecurity Security Advisory. BT Home Hub SSID Script Injection Vulnerability. 10 th May Contents

Host-based Protection for ATM's

Transcription:

Your texte here. CVE-2012-1535 Adobe Flash Player Integer Overflow Vulnerability Analysis October 11 th, 2012 Brian MARIANI & Frédéric BOURLA

A FEW WORDS ABOUT FLASH PLAYER Your Adobe texte Flash here is. a multimedia platform used to add animation, video, and interactivity to web pages. Flash manipulates vectors and graphics to provide animation of text, drawings and images. It supports bidirectional streaming of audio and video. It can capture user inputs via mouse, keyboard, microphone and camera. Flash contains an object-oriented language called ActionScript. It supports automation via the JavaScript Flash language.

ADOBE FLASH PLAYER HISTORY Flash originated with the application SmartSketch, developed by Jonathan Your Gay. texte here. It was published by FutureWave Software, which was founded by Charlie Jackson, Jonathan Gay and Michelle Welsh. As the Internet became more popular, FutureWave added cell animation editing to the vector drawing capabilities of SmartSketch and released FutureSplash Animator on multiple platforms. FutureWave approached Adobe Systems with an offer to sell them FutureSplash in 1995, but Adobe turned them down at that time. In 1996, FutureSplash was acquired by Macromedia and released as Flash, contracting "Future" and "Splash". Flash is currently developed and distributed by Adobe Systems, as the result of their purchase of Macromedia in 2005.

FLASH IS NOT AN EXCEPTION Your Just texte as other here widespread. software Adobe Flash Player has been heavily audited by cybercriminals the last years. Their main objective is to find high-risk security vulnerabilities which does almost not need user's interactivity in order to fully compromise a remote system. Since 2006 Adobe Flash security problems have raised considerably. Tens of vulnerabilities have been reported the last year. The following slides confirms this issue by giving an overview of Adobe Flash Player vulnerabilities reported between 2006 and 2011.

SOME STATISTICS Your texte here. Reported vulnerabilities in Adobe Flash Player

SOME BAD NEWS ABOUT FLASH PLAYER Your texte here. c

TIMELINE OF THE CVE 2012-1535 In this document we will be focused in a pretty recent Adobe Flash Player Your vulnerability texte here tagged. as CVE-2012-1535 by Mitre. Before the 14 th August 2012 the flaw was seriously abused over Internet and mainly distributed through malicious Microsoft Word documents. [2] [4] On 14 th August 2012 Adobe has finally released a patch. [2] On August 15 th 2012 Alien Vault Labs [4] has published a brief analysis based on a malicious Microsoft Office Word documents with an embedded SWF file. The 17 th August 2012 Mila Parkour from Contagiodump [3] has posted some of these samples. Finally, the 17 th August 2012 Rapid7 has published a working exploit for IE 6/7 and 8 on Windows XP SP3 and finally updated the exploit for IE 9 on Windows 7 SP1.

SAMPLES FROM CONTAGIODUMP (1) Mila Parkour provided us with some of the aforementioned samples in order to Your texte here. dig about this vulnerability. These ones are Microsoft Word documents with an embedded SWF document. After a trivial analysis one can easily understand that these files contain suspicious data. There is enough doubtful information to realize that they were intended to launch a client side exploit in Adobe Flash Player. The following slides show some key information found in the sample 7E3770351AED43FD6C5CAB8E06DC0300-iPhone 5 Battery.doc.

SAMPLES FROM CONTAGIODUMP (2) The Shockwave Flash object is easily identifiable. Your texte here.

SAMPLES FROM CONTAGIODUMP (3) The ActionScript heapspray code and the payload can definitely be recognized. Your texte here.

SAMPLES FROM CONTAGIODUMP (4) Your Eventually texte here a strange. font description named Pspop can be found embedded into the SWF document.

VULNERABILITY DETAILS Your The texte flaw relies here on. the ActiveX component of Adobe Flash Player before version 11.3.300.271. The code responsible for parsing the OTF file format (OpenType Format) triggers an exception when the file has a large ntables value contained in the kerning. After the code parses the OTF file, an integer overflow occurs and corrupts the memory. In this document we analyze the process which includes the ActionScript heap spray process finishing by triggering the vulnerability which permits code execution. Our lab environment is an English Windows XP SP3 operating system with Internet Explorer version 7 with Flash 11_3_300_268 installed.

INTEGER OVERFLOWS Your An integer texte here overflow. vulnerability differs a lot from other kinds of security issues such as buffer or heap overflows. One cannot hijack instantly the execution flow or directly write at arbitrary memory locations. Not all integer overflows are actually exploitable. Many can lead to a denial of service but not always to arbitrary code execution. What is true is that very often one could force a program to read or grab an erroneous value and this can contribute to create serious problems into the program s logic. Owing to all these explanations, integer overflows vulnerabilities are relatively difficult to spot and to exploit. [12]

HEAP SPRAYING WITH ACTIONSCRIPT ActionScript is a programming language used in Adobe Air and Flash. Your texte here. Heap spraying is an exploitation technique which consist in placing a specific sequence of bytes at a predictable memory location of the targeted process by allocating chunks of memory. It also provides a way to allocate chunks in the heap area. In the CVE-2009-1869 vulnerability a security researcher named Roee Hay used an ActionScript heap spraying in his exploit. The Actionscript code was originally published over Internet. [15] If you are willing to know more about heap spraying, please read this this document.

THE ACTIONSCRIPT HEAPSPRAY CODE Your texte here.

THE CODE DETAILS The most important lines are 3, 4 and from 17 up to 29. Your texte here. At line 3 the class array is used to create an object named Memory. At line 4 the size of the memory chunk is defined to 0x100000 bytes. At line 19, the function dospray defines a variable named chunk of the bytearray class. The while loop at line 21 will write the second argument using the ascii character set in the memory chunk. Lastly at line 26 a for loop will fill up the memory object with the desired number of chunks. The next slide show the results of this piece of code.

THE RESULTS OF HEAPSPRAYING Welcome to the 0x0c world! Your texte here. Let s analyze the vulnerability now.

VULNERABILITY ANALYSIS (1) Your After texte triggering here. a working exploit, the call stack is as described in the image below:

VULNERABILITY ANALYSIS (2) Your One texte can observe here. that the return addresses start always from the 0x10000000 base memory address. This is clearly because we are dealing with a non-aslr (address space layout randomization) windows module.

VULNERABILITY ANALYSIS (3) Your At the texte line here 00 it. is possible to identify the 0x0c0c0c0b address which confirms that the flow of execution has been successfully hijacked.

VULNERABILITY ANALYSIS (4) Your Taking texte into here consideration. the last return address in the previous call stack minus ten bytes lets us discover the instruction who gains code execution. An EAX pointer seems to allow the attacker to redirect program flow control.

VULNERABILITY ANALYSIS (5) Your In order texte to here trace. the source of the problem we put a breakpoint at the entry point of the function containing the instruction responsible of triggering the exploit. After running the exploit again and breaking at the entry point, the last return address of the call stack tells us about the address 0x104354e4.

VULNERABILITY ANALYSIS (6) Your Just texte before here the instruction. at the address 0x104354e4 is a call which seems to jump to the function who gets the data from the malformed OTF file. We will call this function issue_func.

VULNERABILITY ANALYSIS (7) Your According texte here to Rapid7. the code responsible for parsing the OTF file format triggers an exception when the file has a large ntables value contained in the kerning. If we refer to the malformed OTF file embedded into the SWF document the ntables value is set to 10000000.

VULNERABILITY ANALYSIS (8) Your After texte Adobe here Flash. loads the malicious SWF document in memory we can find the malformed OTF format and the crafted data some bytes farther in memory.

VULNERABILITY ANALYSIS (9) Your When texte Adobe here Flash. parses the OTF file the 10000000 value is passed during the execution of the issue_function. The instruction at the address 0x104418C0 reads the large ntable value 10000000.

VULNERABILITY ANALYSIS (10) Your Later texte the instruction here. SHL EAX, 4 at the address 0x104418c9 logically shifts the EAX register 4 bits to the left. This operation converts the EAX register value to ZERO, leading to an integer overflow. The erroneous value is then pushed into the stack at the instruction 0x104418cc. In the shifting instruction Adobe Flash does an operation over an invalid value and this is exactly what contributes to create serious problems into the program's logic but more importantly into the memory area. The integer overflow corrupts memory in such a way that it is possible to later gain code execution.

VULNERABILITY ANALYSIS (11) Your The texte code continues here. and reaches a call to a function which will parse the crafted data from the malformed OTF file. This function is resolved at the address 0x10442237.

VULNERABILITY ANALYSIS (12) Your In the texte heart here of. this function, the previously erroneous value pushed into the stack (00000000) will be taken at the instruction 0x10442261. When the code reaches this function for the third time the ECX register points to the beginning of the Kern Table. At this moment it starts to parse the data with the use of the EAX register as the offset reference.

VULNERABILITY ANALYSIS (13) At the fifth entry in the function the EAX register will be equal to 8. Your texte here. After adding the EAX and ECX registers, ECX will point to the crafted data which will later corrupt the memory.

VULNERABILITY ANALYSIS (14) Your At the texte end here of the. function EBX and EAX values will be equal to the 1e0cffe8 value. This value will be slightly modified and finally written into the memory pointed by the ESI register by four instructions located in the issue_func function.

VULNERABILITY ANALYSIS (15) Your Here s texte the here memory. corruption after the code has processed the previously described instructions many times.

VULNERABILITY ANALYSIS (16) Your From texte the issue_func here. function, the code will push the ESI register and calls the function at the address 0x1044167b. This is the function which triggers the payload.

VULNERABILITY ANALYSIS (17) At this moment the ESI register points to the corrupted memory. Your texte here. The EAX register gets the value pointed by ESI at the address 0x10441687. Eventually after reaching the CALL instruction the arbitrary code execution is reached.

MITIGATE THE RISK Updating is the best choice for protecting yourself from this specific threat. [14] Your texte here. When this kind of threats is delivered through Microsoft Office documents some mitigations techniques are available, such as: Using EMET. Setting the protected view as the default mode. Enforcing ActiveX security settings.

REFERENCES Your texte here. [1] http://en.wikipedia.org/wiki/adobe_flash [2] http://www.adobe.com/support/security/bulletins/apsb12-18.html [3] http://contagiodump.blogspot.ch/2012/08/cve-2012-1535-samples-and-info.html [4] http://labs.alienvault.com/labs/index.php/2012/cve-2012-1535-adobe-flash-being-exploited-in-the-wild/ [5] https://community.rapid7.com/community/metasploit/blog/2012/08/17/adobe-flash-player-exploit-cve- 2012-1535-now-available-for-metasploit [6] http://downloads.securityfocus.com/vulnerabilities/exploits/55009.rb [7] http://feliam.wordpress.com/2010/02/15/filling-adobes-heap/ [8] http://livedocs.adobe.com/flash/9.0_fr/actionscriptlangrefv3/array.html [9] http://help.adobe.com/en_us/as3/dev/ws5b3ccc516d4fbf351e63e3d118676a5388-8000.html [10] https://www.corelan.be/index.php/2011/12/31/exploit-writing-tutorial-part-11-heap-spraying-demystified/ [11] https://community.rapid7.com/community/metasploit/blog/2012/08/17/adobe-flash-player-exploit-cve- 2012-1535-now-available-for-metasploit [12] http://www.phrack.org/issues.html?issue=60&id=10 [13] http://blogs.technet.com/b/mmpc/archive/2012/08/31/a-technical-analysis-on-cve-2012-1535-adobeflash-player-vulnerability-part-2.aspx [14] http://get.adobe.com/flashplayer [15] http://code.google.com/p/roeehay/source/browse/trunk/adobe_flash_cve-2009-1869/src/heaplib.as?r=2

THANK YOU FOR READING! Your texte here. Your questions are always welcome! brian.mariani@htbridge.com frederic.bourla@htbridge.com