6 ms·
Windows Critical ICMP Remote Code Execution Vulnerability
- zorlack 4y ago> To trigger the vulnerable code path, an application on the target must be bound to a raw socket. What is a "raw socket" in this context?
- MadsRC 4y agoThings like wireshark binds to a raw socket rather than using the Windows API
- Someone1234 4y agoThe sockets API is a Windows API, and Wireshark does not use it. Instead it uses Npcap, a custom kernel driver. A raw socket allows creation/consumption of bespoke packet types (i.e. not Tcp/Udp). In this case ICMP.
- dboreham 4y agoRaw is a protocol type in the socket api allowing the application to send and receive arbitrary packets (e.g. not packets generated by the system's TCP implementation).
- Noxwizard 4y agoThis means the listening socket was created using SOCK_RAW as opposed to SOCK_STREAM or SOCK_DGRAM. Raw sockets are used for working with ICMP, doing packet sniffing, sending some types of custom TCP packets, etc. Basically anything that isn't UDP or TCP, you'll need a raw socket for.
- cryptonector 4y agoHistorically programs like `ping` and `traceroute` use raw sockets. Using raw sockets requires privilege, which is why those historically have been set-uid on Unix systems.
- Noxwizard 4y agoIndeed. Windows requires elevation for raw sockets as well. The ping binary works without elevation by using the IP Helper Win32 API's ICMP functions: https://learn.microsoft.com/en-us/windows/win32/api/icmpapi/nf-icmpapi-icmpsendecho2ex https://learn.microsoft.com/en-us/windows/win32/api/icmpapi/...
- drewcoo 4y agohttps://learn.microsoft.com/en-us/windows/win32/winsock/service-provided-raw-sockets-2 https://learn.microsoft.com/en-us/windows/win32/winsock/serv... And here they explain that if you use SOCK_RAW, you should look out for bad datagrams: https://learn.microsoft.com/en-us/windows/win32/winsock/tcp-ip-raw-sockets-2 https://learn.microsoft.com/en-us/windows/win32/winsock/tcp-...
- cryptonector 4y agoSo is this a vulnerability in specific raw sockets applications (i.e., you could get it right in the application), or a vulnerability in the Windows kernel's TCP/IP stack that is only exploitable when there is a raw sockets application running?
- tracker1 4y agoI know there's some limits to the surface of this... but it seems that could precisely be triggered by certain types of security software, ironically designed to protect such systems. Eww...
- Run_DOS_Run 4y agoIt's far easier to find 0-days in antivirus software than in common-used operating systems or servers (IIS, Nginx, ...). The attack surface is huge, the software often very old and written in a memory-unsafe language like C and C++ for performance-reasons. I reverse engineered some antivirus products myself and the quality of most AVs is pretty bad. AFL (American Fuzzy Lop) without a custom mutator crashed some of them in less than 15 minutes at the most trivial parts like parsing a PE-file. Also snakeoil-features like "anti-rootkit scanner" just compare hashes (sometimes MD5-hashes) of installed drivers. In past a rootkit could circumvent such scanner with IAT-hooking. In 2023 those scanners are obsolete anyway. Also antivirus 0-days are far cheaper than for other software.* * https://zerodium.com/program.html https://zerodium.com/program.html
- londons_explore 4y agoSo any default services bind to raw sockets? I can't think of any... Which in turn means that most systems probably aren't vulnerable. On windows I think you need admin rights to open a raw socket, which means that only admins can pwn the machine...
- throwbadubadu 4y agoWhat about VPN clients, I'd assume some do?