3 ms·
The engine is not sandboxed. I will speak only for the Windows product though, because this is the only one I looked at in detail. (But the Linux engine is not
by landave 9y ago
The engine is not sandboxed. I will speak only for the Windows product though, because this is the only one I looked at in detail. (But the Linux engine is not sandboxed either).
This is X86 code [1] running as NT AUTHORITY\SYSTEM. Hence, successful exploitation for arbitrary remote code execution (as NT AUTHORITY\SYSTEM) only requires circumventing the stack canary.
As mentioned in footnote 6 of the article, they seem to use Control Flow Guard (CFG) on the latest Windows platforms. However, just as the stack canary, this is only a mitigation. It does not make exploitation impossible, it just makes it a bit harder.
[1] In the article, I present a pseudocode version of the relevant function. If you are interested in the actual X86 instructions, you might want to look at footnote 4 of the article.