The attached testcase was found by fuzzing DEX files, and results in a heap
overflow with a wild memcpy. Note that Kaspersky catch exceptions and continue
execution, so running into unmapped pages doesn't terminate the process, this
should make exploitation quite realistic.
(bb8.ac0): Access violation - code c0000005 (first chance)
First chance exceptions are reported before any exception handling.
This exception may be expected and handled.
eax=0c0b2074 ebx=ffffffff ecx=3ffd419c edx=00000003 esi=0c161a01 edi=0c170000
eip=72165157 esp=046ceed8 ebp=046ceee0 iopl=0 nv up ei pl nz na po nc
cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00010202
avengine_dll!ekaGetObjectFactory+0x51537:
72165157 f3a5 rep movs dword ptr es:[edi],dword ptr [esi]
0:023> dd edi
0c170000 ???????? ???????? ???????? ????????
0c170010 ???????? ???????? ???????? ????????
0c170020 ???????? ???????? ???????? ????????
0c170030 ???????? ???????? ???????? ????????
0c170040 ???????? ???????? ???????? ????????
0c170050 ???????? ???????? ???????? ????????
0c170060 ???????? ???????? ???????? ????????
0c170070 ???????? ???????? ???????? ????????
0:023> dd esi
0c161a01 00000000 00000000 00000000 00000000
0c161a11 00000000 00000000 00000000 00000000
0c161a21 00000000 00000000 00000000 00000000
0c161a31 00000000 00000000 00000000 00000000
0c161a41 00000000 00000000 00000000 00000000
0c161a51 00000000 00000000 00000000 00000000
0c161a61 00000000 00000000 00000000 00000000
0c161a71 00000000 00000000 00000000 00000000
0:023> kvn1
# ChildEBP RetAddr Args to Child
00 046ceee0 15c01af7 0c0c0674 0c0b2075 ffffffff
avengine_dll!ekaGetObjectFactory+0x51537
This vulnerability is exploitable for remote code execution as NT
AUTHORITY\SYSTEM.
This bug is subject to a 90 day disclosure deadline. If 90 days elapse
without a broadly available patch, then the bug report will automatically
become visible to the public.
Original issue reported on code.google.com by tav...@google.com on 10 Sep 2015 at 9:59
Original issue reported on code.google.com by
tav...@google.com
on 10 Sep 2015 at 9:59Attachments: