File Hijacking Vulnerability: The Elephant in the Room
Chendong Yu, Yang Xiao, Jie Lu, Yuekang Li, Yeting Li, Lian Li, Yifan Dong, Jian Wang, Jingyi Shi, Defang Bo, Wei Huo
Abstract
—Files are a significant attack vector for security boundary violation, yet a systematic understanding of the vulnerabilities underlying these attacks is lacking. To bridge this gap, we present a comprehensive analysis of File Hijacking Vulnerabilities (FHVulns), a type of vulnerability that enables attackers to breach security boundaries through the manipulation of file content or file paths. We provide an in-depth empirical study on 268 well-documented FHVuln CVE records from January 2020 to October 2022. Our study reveals the origins and triggering mechanisms of FHVulns and highlights that existing detection techniques have overlooked the majority of FHVulns. As a result, we anticipate a significant prevalence of zero-day FHVulns in software. We developed a dynamic analysis tool, J ERRY , which effectively detects FHVulns at runtime by simulating hijacking actions during program execution. We applied J ERRY to 438 popular software programs from vendors including Microsoft, Google, Adobe, and Intel, and found 339 zero-day FHVulns. We reported all vulnerabilities identified by J ERRY to the corresponding vendors, and as of now, 84 of them have been confirmed or fixed, with 51 CVE IDs granted and $83,400 bug bounties earned.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c9f06b54-1ac9-4500-a565-da95dd33a27fCited by top-tier papers9
- Detecting Broken Object-Level Authorization Vulnerabilities in Database-Backed ApplicationsYongheng Huang, Chenghang Shi, Jie Lu, Haofeng Li et al.CCS 2024 · 4 citations
- DualStrike: Accurate, Real-time Eavesdropping and Injection of Keystrokes on Commodity KeyboardsXiaomeng Chen, Jike Wang, Zhenyu Chen, Qi Alfred Chen et al.NDSS 2026 · 1 citation
- Wormholes in the File System: Understanding the Misunderstanding of SymlinksYongheng Liu, Lei Zhang, Yuhang Zhao, Yuzhou HeUSENIX Security 2026
- Be Aware of What You Let Pass: Demystifying URL-based Authentication Bypass Vulnerability in Java Web ApplicationsQiyi Zhang, Fengyu Liu, Zihan Lin, Yuan ZhangCCS 2025
- LinkGuard: A Lightweight State-Aware Runtime Guard Against Link Following Attacks in Windows File SystemBocheng Xiang, Yuan Zhang, Hao Huang, Fengyu Liu et al.NDSS 2026
Builds on11
- CodeT5: Identifier-aware Unified Pre-trained Encoder-Decoder Models for Code Understanding and GenerationYue Wang, Weishi Wang, Shafiq R. Joty, Steven C. H. HoiEMNLP 2021 · 1,224 citations
- The Cracked Cookie Jar: HTTP Cookie Hijacking and the Exposure of Private InformationSuphannee Sivakorn, Iasonas Polakis, Angelos D. KeromytisS&P 2016 · 86 citations
- KEPLER: Facilitating Control-flow Hijacking Primitive Evaluation for Linux Kernel VulnerabilitiesWei Wu, Yueqi Chen, Xinyu Xing, Wei ZouUSENIX Security 2019 · 75 citations
- Sharing More and Checking Less: Leveraging Common Input Keywords to Detect Bugs in Embedded SystemsLibo Chen, Yanhao Wang, Quanpu Cai, Yunfan Zhan et al.USENIX Security 2021 · 71 citations
- O Single Sign-Off, Where Art Thou? An Empirical Analysis of Single Sign-On Account Hijacking and Session Management on the WebMohammad Ghasemisharif, Amrutha Ramesh, Stephen Checkoway, Chris Kanich et al.USENIX Security 2018 · 63 citations
Related papers
- Pig in a Poke: Automatically Detecting and Exploiting Link Following Vulnerabilities in Windows File OperationsBocheng Xiang, Yuan Zhang, Fengyu Liu, Hao Huang et al.USENIX Security 2025
- Windows plays Jenga: Uncovering Design Weaknesses in Windows File System SecurityDong-uk Kim, JunYoung Park, Sanghak Oh, Hyoungshick Kim et al.CCS 2025
- XSSky: Detecting XSS Vulnerabilities through Local Path-Persistent FuzzingYoukun Shi, Yuan Zhang, Tianhao Bai, Feng Xue et al.USENIX Security 2025
- Sys: A Static/Symbolic Tool for Finding Good Bugs in Good (Browser) CodeFraser Brown, Deian Stefan, Dawson R. EnglerUSENIX Security 2020
- Demystifying Exploitable Bugs in Smart ContractsZhuo Zhang, Brian Zhang, Wen Xu, Zhiqiang LinICSE 2023 · 80 citations
