>_0xFORUM
Sign in

CVE-2024 notes: a public n-day after the patch landed

in Exploits23 replies5.2k views

Patched, public, vendor advisory is out. This thread is for defenders catching up. Classic integer wrap in a length field before a memcpy into a pool allocation.

Exploitability on modern Windows is messy because of pool encoding, but the crash is easy to hit with a malformed file. Hunt the old immediate. Do not ask for a working exploit.

Refs: CVE Program · MSRC · NVD

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 23 REPLIES

I still keep a paper notebook for this kind of note. You wrote «Patched, public, vendor advisory is out». That is the sentence I keep. Date your heap notes. 2012 grooming diagrams are history. Version in my shot: current lab snapshot, not last year's blog.

Good. Dated shot, version in the post. You wrote «Patched, public, vendor advisory is out». That is the sentence I keep. system() on a user path is the class. execve with argv is the patch. Pinned a comment at 0x140002170 in the listing.

@hunt

I still keep a paper notebook for this kind of note. You wrote «Patched, public, vendor advisory is out». That is the sentence I keep. Date

I am not moving this to DMs so you can yell. Stay on the class. Good. Dated shot, version in the post. «CVE-2024 notes: a public n-day after the patch landed» — specifically Patched, public, vendor advisory is out. No samples, even public corpus files. Hashes and links. Attachments get pulled. My note id for this: d5-01.

@ledgr

Came back to this after a coffee. Still hold. «CVE-2024 notes: a public n-day after the patch landed» — specifically Patched, public, vendor

I read the patch. You read a tweet. Those are not the same source. Bookmarking this for the lab wiki. «CVE-2024 notes: a public n-day after the patch landed» — specifically Patched, public, vendor advisory is out. Date your heap notes. 2012 grooming diagrams are history. Took me 9 hours the first time.

@juniorfx

Good. Dated shot, version in the post. You wrote «Patched, public, vendor advisory is out». That is the sentence I keep. system() on a user

That is not what the listing shows. You are arguing a vibe. This matches a public n-day class from last patch Tuesday. The load-bearing line: Patched, public, vendor advisory is out. Date your heap notes. 2012 grooming diagrams are history. Did you force-create the function or did auto-analysis luck into it? Took me 8 hours the first time.

@kingsleyo

This matches a public n-day class from last patch Tuesday. The load-bearing line: Patched, public, vendor advisory is out. Date your heap no

Came back to this after a coffee. Still hold. «CVE-2024 notes: a public n-day after the patch landed» — specifically Patched, public, vendor advisory is out. If the thread slides toward a live target, lock it. I will report it. I still have the snapshot named expl-213-pre.

I tried the naive path first and wasted a morning. On «CVE-2024 notes: a public n-day after the patch landed»: Patched, public, vendor advisory is out. A saturating add that hangs is not a complete patch. Hunt the hang too. What did you key the join on — PID or process GUID? I reproduced it on lab build 1181.

@bitwise

Please keep the hashes and drop the mystery zips. «CVE-2024 notes: a public n-day after the patch landed» — specifically Patched, public, ve

This is the writeup I wanted when I was stuck. «CVE-2024 notes: a public n-day after the patch landed» — specifically Patched, public, vendor advisory is out. Date your heap notes. 2012 grooming diagrams are history. I still have the snapshot named expl-213-pre.

@kiber_lisa

I tried the naive path first and wasted a morning. On «CVE-2024 notes: a public n-day after the patch landed»: Patched, public, vendor advis

You skipped isolation and then asked why the box is dirty. That is on you. I dumped after OEP and then did this. «CVE-2024 notes: a public n-day after the patch landed» — specifically Patched, public, vendor advisory is out. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Took me 2 hours the first time.

This is the writeup I wanted when I was stuck. On «CVE-2024 notes: a public n-day after the patch landed»: Patched, public, vendor advisory is out. Date your heap notes. 2012 grooming diagrams are history. Version in my shot: current lab snapshot, not last year's blog.

Also: Canonicalize last. Concatenate after realpath is how .. comes back.

@authz

This is the writeup I wanted when I was stuck. On «CVE-2024 notes: a public n-day after the patch landed»: Patched, public, vendor advisory

I am not moving this to DMs so you can yell. Stay on the class. Please keep the hashes and drop the mystery zips. «CVE-2024 notes: a public n-day after the patch landed» — specifically Patched, public, vendor advisory is out. If you wrap memcpy, I want the check on every path. If anyone DMs me a zip I will not open it. Hash in-thread.

Did this on ARM64 last week — same shape, different pain. You wrote «Patched, public, vendor advisory is out». That is the sentence I keep. OOB read is a leak until proven otherwise. In the notes, not in a PoC. I will +rep a listing and −rep a vibe. That is the deal.

@n0va

Did this on ARM64 last week — same shape, different pain. You wrote «Patched, public, vendor advisory is out». That is the sentence I keep.

Call-convention guess is not evidence. If you only have the decompiler, you do not have the bug. You wrote «Patched, public, vendor advisory is out». That is the sentence I keep. Date your heap notes. 2012 grooming diagrams are history. Took me 9 hours the first time.

This is the kind of thread that should be a sticky and is not. On «CVE-2024 notes: a public n-day after the patch landed»: Patched, public, vendor advisory is out. Patched class only. Hunt the old immediate. Do not ask for a trigger file. Is the hang the incomplete patch, or a second bug? My note id for this: d5-08.

@oscar

This is the kind of thread that should be a sticky and is not. On «CVE-2024 notes: a public n-day after the patch landed»: Patched, public,

Do not call people skids because they use Ghidra. Bookmarking this for the lab wiki. You wrote «Patched, public, vendor advisory is out». That is the sentence I keep. OOB read is a leak until proven otherwise. In the notes, not in a PoC. Took me 8 hours the first time.

@primealex

Bookmarking this for the lab wiki. You wrote «Patched, public, vendor advisory is out». That is the sentence I keep. OOB read is a leak unti

I disagree with the tone, not the bytes. On «CVE-2024 notes: a public n-day after the patch landed»: Patched, public, vendor advisory is out. Date your heap notes. 2012 grooming diagrams are history. Version in my shot: current lab snapshot, not last year's blog.

@resrch

I disagree with the tone, not the bytes. On «CVE-2024 notes: a public n-day after the patch landed»: Patched, public, vendor advisory is out

You are describing a live target. Stop. Patched class only. Came back to this after a coffee. Still hold. The load-bearing line: Patched, public, vendor advisory is out. No samples, even public corpus files. Hashes and links. Attachments get pulled. Pinned a comment at 0x140002396 in the listing.

Please keep the hashes and drop the mystery zips. The load-bearing line: Patched, public, vendor advisory is out. Date your heap notes. 2012 grooming diagrams are history. Took me 4 hours the first time.

Also: system() on a user path is the class. execve with argv is the patch.

@sigmaxx

Please keep the hashes and drop the mystery zips. The load-bearing line: Patched, public, vendor advisory is out. Date your heap notes. 2012

Take the telegram pitch to the bin. Market listing or nothing. I would have written the opposite conclusion a year ago. You wrote «Patched, public, vendor advisory is out». That is the sentence I keep. Canonicalize last. Concatenate after realpath is how .. comes back. Is the hang the incomplete patch, or a second bug? Version in my shot: current lab snapshot, not last year's blog.

I ran this on a licensed corpus binary. The load-bearing line: Patched, public, vendor advisory is out. OOB read is a leak until proven otherwise. In the notes, not in a PoC. Took me 4 hours the first time.

@tango

I ran this on a licensed corpus binary. The load-bearing line: Patched, public, vendor advisory is out. OOB read is a leak until proven othe

Quote the bytes or sit down. This matches a public n-day class from last patch Tuesday. On «CVE-2024 notes: a public n-day after the patch landed»: Patched, public, vendor advisory is out. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Version in my shot: current lab snapshot, not last year's blog.

@vectrx

This matches a public n-day class from last patch Tuesday. On «CVE-2024 notes: a public n-day after the patch landed»: Patched, public, vend

I reproduced it twice before I believed you. «CVE-2024 notes: a public n-day after the patch landed» — specifically Patched, public, vendor advisory is out. A saturating add that hangs is not a complete patch. Hunt the hang too. I wrote a 12-line script and then threw it away. The listing was enough.

@wanx

I reproduced it twice before I believed you. «CVE-2024 notes: a public n-day after the patch landed» — specifically Patched, public, vendor

You are treating a checksum as a signature again. Please keep the hashes and drop the mystery zips. You wrote «Patched, public, vendor advisory is out». That is the sentence I keep. Date your heap notes. 2012 grooming diagrams are history. My note id for this: d5-17.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.