Twenty Year Anniversary

Chakra CFG Bypass By Overwriting JavaScript Bytecode

Chakra CFG Bypass By Overwriting JavaScript Bytecode
Posted Dec 5, 2017
Authored by Ivan Fratric, Google Security Research

Chakra suffers from a CFG bypass by overwriting JavaScript bytecode.

tags | advisory, javascript
MD5 | 9e57eaebd2d21e12b8ff2602894b0871

Chakra CFG Bypass By Overwriting JavaScript Bytecode

Change Mirror Download
Chakra: CFG bypass by overwriting JavaScript bytecode 




Assume an attacker has the ability to overwrite Chakra's bytecode, either through a read/write primitive or through an overflow type vulnerability. Let's take a look at the ArgOut_A bytecode instruction which is implmented in InterpreterStackFrame::OP_ArgOut_A:

template <class T>
void InterpreterStackFrame::OP_ArgOut_A(const unaligned T * playout)
{
SetOut(playout->Arg, GetReg(playout->Reg));
}

And let's take a look at SetOut and GetReg functions:

inline void InterpreterStackFrame::SetOut(ArgSlot outRegisterID, Var aValue)
{
Assert(m_outParams + outRegisterID < m_outSp);
m_outParams[outRegisterID] = aValue;
}

template <typename RegSlotType>
Var InterpreterStackFrame::GetReg(RegSlotType localRegisterID) const
{
Var value = m_localSlots[localRegisterID];
ValidateRegValue(value);
return value;
}

Note there is an Assert() in SetOut() but that won't affect the behavior of the release version. Similarly, ValidateRegValue will only actually perform validation in the debug build.

If we can corrupt the bytecode of the ArgOut_A instruction (pointed to by playout) we can *read* an out-of-bounds value in GetReg() and then also *write* it out-of-bounds in SetOut. Note that out-of-bounds read/write here is limited in the sense that both playout->Arg and playout->Reg are 8-bit values but it is sufficient for our purpose.

If we already have a read/write primitive, this normally wouldn't give us new capabilities. But note that both m_outParams and m_localSlots actually point on the stack. Thus modifying the ArgOut_A layout will also give us a limited read/write primitive on the stack, which allows us to bypass CFG. For example, we might read some value we control in GetReg() and then use SetOut() to overwrite a return address, thus bypassing CFG. We might also read out a memory from the stack using GetReg() and then write it somewhere where we can extract it using JavaScript.

Note #1: There are other instructions that behave similarly such as ProfiledArgOut_A and ArgOut_Env

Note #2: These are most likely not the only bytecode instructions that allow an attacker to bypass CFG. In fact by dumb-fuzzing the bytecode and then interpreting it it is fairly easy to get RIP to point outside of the executable memory.


This bug is subject to a 90 day disclosure deadline. After 90 days elapse
or a patch has been made broadly available, the bug report will become
visible to the public.




Found by: ifratric

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

Want To Donate?


Bitcoin: 18PFeCVLwpmaBuQqd5xAYZ8bZdvbyEWMmU

File Archive:

August 2018

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    19 Files
  • 2
    Aug 2nd
    17 Files
  • 3
    Aug 3rd
    16 Files
  • 4
    Aug 4th
    1 Files
  • 5
    Aug 5th
    1 Files
  • 6
    Aug 6th
    19 Files
  • 7
    Aug 7th
    15 Files
  • 8
    Aug 8th
    9 Files
  • 9
    Aug 9th
    7 Files
  • 10
    Aug 10th
    10 Files
  • 11
    Aug 11th
    1 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    14 Files
  • 14
    Aug 14th
    18 Files
  • 15
    Aug 15th
    38 Files
  • 16
    Aug 16th
    16 Files
  • 17
    Aug 17th
    22 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2018 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close