xti9er / google-security-research

Automatically exported from code.google.com/p/google-security-research
0 stars 0 forks source link

Kaspersky Antivirus DEX file format memory corruption #529

Closed GoogleCodeExporter closed 8 years ago

GoogleCodeExporter commented 8 years ago
The attached testcase was found by fuzzing DEX files, and results in a heap 
overflow with a wild memcpy. Note that Kaspersky catch exceptions and continue 
execution, so running into unmapped pages doesn't terminate the process, this 
should make exploitation quite realistic.

(bb8.ac0): Access violation - code c0000005 (first chance)
First chance exceptions are reported before any exception handling.
This exception may be expected and handled.
eax=0c0b2074 ebx=ffffffff ecx=3ffd419c edx=00000003 esi=0c161a01 edi=0c170000
eip=72165157 esp=046ceed8 ebp=046ceee0 iopl=0         nv up ei pl nz na po nc
cs=0023  ss=002b  ds=002b  es=002b  fs=0053  gs=002b             efl=00010202
avengine_dll!ekaGetObjectFactory+0x51537:
72165157 f3a5            rep movs dword ptr es:[edi],dword ptr [esi]
0:023> dd edi
0c170000  ???????? ???????? ???????? ????????
0c170010  ???????? ???????? ???????? ????????
0c170020  ???????? ???????? ???????? ????????
0c170030  ???????? ???????? ???????? ????????
0c170040  ???????? ???????? ???????? ????????
0c170050  ???????? ???????? ???????? ????????
0c170060  ???????? ???????? ???????? ????????
0c170070  ???????? ???????? ???????? ????????
0:023> dd esi
0c161a01  00000000 00000000 00000000 00000000
0c161a11  00000000 00000000 00000000 00000000
0c161a21  00000000 00000000 00000000 00000000
0c161a31  00000000 00000000 00000000 00000000
0c161a41  00000000 00000000 00000000 00000000
0c161a51  00000000 00000000 00000000 00000000
0c161a61  00000000 00000000 00000000 00000000
0c161a71  00000000 00000000 00000000 00000000
0:023> kvn1
 # ChildEBP RetAddr  Args to Child              
00 046ceee0 15c01af7 0c0c0674 0c0b2075 ffffffff 
avengine_dll!ekaGetObjectFactory+0x51537

This vulnerability is exploitable for remote code execution as NT 
AUTHORITY\SYSTEM.

This bug is subject to a 90 day disclosure deadline. If 90 days elapse
without a broadly available patch, then the bug report will automatically
become visible to the public.

Original issue reported on code.google.com by tav...@google.com on 10 Sep 2015 at 9:59

Attachments:

GoogleCodeExporter commented 8 years ago
This issue was resolved on November 16th.

Original comment by tav...@google.com on 16 Nov 2015 at 7:23