Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Enhancement] Add PassMark LPE-ready driver #3

Closed
hfiref0x opened this issue Apr 27, 2021 · 1 comment
Closed

[Enhancement] Add PassMark LPE-ready driver #3

hfiref0x opened this issue Apr 27, 2021 · 1 comment
Labels
enhancement New feature or request good first issue Good for newcomers

Comments

@hfiref0x
Copy link
Owner

Demo for references, https://gist.github.com/hfiref0x/33985b7694c06bc8ee6d8385efadb85e

Driver details:
SHA256, EV certificate, full of bugs and vulnerabilities.
Dedicated previous CVE id: CVE-2020-15481, CVE-2020-15480

CVE vendor response:
CVE-2020-15480, Ban LSTAR and SYSENTER_EIP_MSR from readmsr IOCTL.
CVE-2020-15481, disputable CVE, when loaded with PassMark software DirectIO driver device despite having default SD will be created with DO_EXCLUSIVE object flags, thus it won't allow multiple handles and potential PoC won't work unless they somehow got into PassMark program address space which require elevation or another exploit. PassMark addressed this with regenerating IOCTL's values and leaving everything as is.

PassMark DirectIO mapping routines for reference https://gist.github.com/hfiref0x/fb822ab89c9f10c46deb172c961ce7bf

@hfiref0x hfiref0x added enhancement New feature or request good first issue Good for newcomers labels Apr 27, 2021
@hfiref0x hfiref0x pinned this issue Apr 27, 2021
@hfiref0x
Copy link
Owner Author

Ref. cdc215d

@hfiref0x hfiref0x mentioned this issue May 2, 2021
@hfiref0x hfiref0x closed this as completed May 2, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request good first issue Good for newcomers
Projects
None yet
Development

No branches or pull requests

1 participant