USENIX Security2026Top-tier venue
Death by a Thousand Drips: Uncovering Critical Resource Leaks in the Windows Ecosystem
Feng Dong, Jianting Gao, Yunpeng Tian, Weifeng Yuan, Mu Zhang, Zesen Ye, Jietao Yang, Zhiniang Peng
Abstract
Windows remote services are a critical attack surface due to their privileged execution and widespread deployment. Under the shared service-host model (svchost.exe), a single resource-exhaustion bug can trigger fate-sharing failures across co-resident services. Yet most vulnerability discovery remains crash-centric and is thus blind to silent, long-horizon resource leaks (e.g., memory/handle exhaustion) that do not cause immediate exceptions, while the closed-source Windows ecosystem limits the applicability of source-level sanitizers. We present REDOSPECTOR, a fuzzing framework for discovering resource-oriented Denial-of-Service (DoS) vulnerabilities in opaque Windows binaries. REDOSPECTOR combines (1) lightweight in-process hook-based telemetry by intercepting native ntdll heap routines, (2) an amplification-based oracle that identifies persistent leaks via repeated execution and growth-trend analysis, and (3) a hybrid seed-generation pipeline that leverages static binary analysis and Large Language Models (LLMs) to reach deep protocol states. Evaluated on the latest builds of Windows 11 (24H2) and Windows Server Preview, REDOSPECTOR uncovers 19 vulnerabilities in core services (including MSMQ, Remote Desktop Gateway, and CDP), leading to 12 assigned CVEs. Microsoft confirmed seven pre-authentication DoS issues in CDP and performed architectural adjustments, demonstrating that REDOSPECTOR can expose resource-mismanagement flaws that evade conventional fuzzing.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 53f5dbcd-d02d-4846-a62a-7afb49659e5dBuilds on19
- SlowFuzz: Automated Domain-Independent Detection of Algorithmic Complexity VulnerabilitiesTheofilos Petsios, Jason Zhao, Angelos D. Keromytis, Suman JanaCCS 2017 · 214 citations
- MemLock: memory usage guided fuzzingCheng Wen, Haijun Wang, Yuekang Li, Shengchao Qin et al.ICSE 2020 · 116 citations
- APISan: Sanitizing API Usages through Semantic Cross-CheckingInsu Yun, Changwoo Min, Xujie Si, Yeongjin Jang et al.USENIX Security 2016 · 107 citations
- Automatically Detecting Error Handling Bugs Using Error SpecificationsSuman Jana, Yuan Jochen Kang, Samuel Roth, Baishakhi RayUSENIX Security 2016 · 79 citations
- Digtool: A Virtualization-Based Framework for Detecting Kernel VulnerabilitiesJianfeng Pan, Guanglu Yan, Xiaocao FanUSENIX Security 2017 · 44 citations
Related papers
- Needle in a Haystack: Automated and Scalable Vulnerability Hunting in the Windows ALPC SeaHaoyi Liu, Feng Dong, Yunpeng Tian, Mu Zhang et al.CCS 2025
- Autonomy Comes with Costs: Detecting Denial-of-Service Vulnerabilities Caused by Resource Abusing in LLM-based AgentsJiaqi Luo, Jiarun Dai, Fengyu Liu, Songyang Peng et al.USENIX Security 2026
- Regulator: Dynamic Analysis to Detect ReDoSRobert McLaughlin, Fabio Pagani, Noah Spahn, Christopher Kruegel et al.USENIX Security 2022
- ReDoSHunter: A Combined Static and Dynamic Approach for Regular Expression DoS DetectionYeting Li, Zixuan Chen, Jialun Cao, Zhiwu Xu et al.USENIX Security 2021 · 20 citations
- LifeFuzz: Lifecycle-Guided Fuzzing for Windows Driver Cross-Handler VulnerabilitiesChendong Yu, Yuekang Li, Yang Xiao, Jie Lu et al.EuroSys 2026
