Detecting Union Type Confusion in Component Object Model
Yuxing Zhang, Xiaogang Zhu, Daojing He, Minhui Xue, Shouling Ji, Mohammad Sayad Haghighi, Sheng Wen, Zhiniang Peng
摘要
Component Object Model (COM) is a binary-interface standard for software components introduced by Microsoft in 1993. Thirty years after its first release, COM is still the basis to support many other core technologies of Microsoft. COM developers used many unions rather than structs in the coding to conserve memory in legacy computers. However, the excessive use of union architecture will most likely introduce type confusion vulnerabilities that can be taken advantage of by 100%-reliable exploits. According to our studies, the problem of union type confusion has long been overlooked and no solutions have been developed for off-the-shelf systems that employ COM. In this paper, we propose COMFUSION, the first tool that detects union type confusion in COM. The crux is to infer union variables and their discriminants in COM binaries. This is challenging since existing type recovery techniques do not support union type in binaries. To resolve this problem, COMFUSION identifies union variables through taint propagation with the help of Microsoft Interface Definition Language (MIDL) files and then searches for union type confusion via symbolic execution. We evaluate COMFUSION on three popular releases of Windows operating system, including Windows 10 1809, Windows 10 21H2, and Windows 11 21H2. COMFUSION successfully found 36 union type confusions. Out of these, 19 type confusions have been confirmed to be capable of corrupting memory, exposing 4 confirmed CVEs.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- GlobalConfusion: TrustZone Trusted Application 0-Days by DesignMarcel Busch, Philipp Mao, Mathias PayerUSENIX Security 2024 · 被引用 4 次
- Death by a Thousand Drips: Uncovering Critical Resource Leaks in the Windows EcosystemFeng Dong, Jianting Gao, Yunpeng Tian, Weifeng Yuan 等USENIX Security 2026
- Be Careful of What You Embed: Demystifying OLE VulnerabilitiesYunpeng Tian, Feng Dong, Haoyi Liu, Meng Xu 等NDSS 2025
它引用的顶会 Paper6
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens 等S&P 2016 · 被引用 1,085 次
- TypeSan: Practical Type Confusion DetectionIstván Haller, Yuseok Jeon, Hui Peng, Mathias Payer 等CCS 2016 · 被引用 97 次
- Regression Greybox FuzzingXiaogang Zhu, Marcel BöhmeCCS 2021 · 被引用 84 次
- OSPREY: Recovery of Variable and Data Structure via Probabilistic Analysis for Stripped BinaryZhuo Zhang, Yapeng Ye, Wei You, Guanhong Tao 等S&P 2021 · 被引用 78 次
- HexType: Efficient Detection of Type Confusion Errors for C++Yuseok Jeon, Priyam Biswas, Scott A. Carr, Byoungyoung Lee 等CCS 2017 · 被引用 67 次
相关 Paper
- COMRace: Detecting Data Race Vulnerabilities in COM ObjectsFangming Gu, Qingli Guo, Lian Li, Zhiniang Peng 等USENIX Security 2022
- Assessing the Impact of Interface Vulnerabilities in Compartmentalized SoftwareHugo Lefeuvre, Vlad-Andrei Badoiu, Yi Chen, Felipe Huici 等NDSS 2023
- Uncontained: Uncovering Container Confusion in the Linux KernelJakob Koschel, Pietro Borrello, Daniele Cono D'Elia, Herbert Bos 等USENIX Security 2023
- Object Flow IntegrityWenhao Wang, Xiaoyang Xu, Kevin W. HamlenCCS 2017 · 被引用 18 次
- Rusted Types: Static Detection of Rust Type Confusion BugsZeyang Zhuang, Wei Meng, Michael R. LyuICSE 2026
