Lune

USENIX Security2026顶会

Death by a Thousand Drips: Uncovering Critical Resource Leaks in the Windows Ecosystem

Feng Dong, Jianting Gao, Yunpeng Tian, Weifeng Yuan, Mu Zhang, Zesen Ye, Jietao Yang, Zhiniang Peng

出版方
2026年份

摘要

Windows remote services are a critical attack surface due to their privileged execution and widespread deployment. Under the shared service-host model (svchost.exe), a single resource-exhaustion bug can trigger fate-sharing failures across co-resident services. Yet most vulnerability discovery remains crash-centric and is thus blind to silent, long-horizon resource leaks (e.g., memory/handle exhaustion) that do not cause immediate exceptions, while the closed-source Windows ecosystem limits the applicability of source-level sanitizers. We present REDOSPECTOR, a fuzzing framework for discovering resource-oriented Denial-of-Service (DoS) vulnerabilities in opaque Windows binaries. REDOSPECTOR combines (1) lightweight in-process hook-based telemetry by intercepting native ntdll heap routines, (2) an amplification-based oracle that identifies persistent leaks via repeated execution and growth-trend analysis, and (3) a hybrid seed-generation pipeline that leverages static binary analysis and Large Language Models (LLMs) to reach deep protocol states. Evaluated on the latest builds of Windows 11 (24H2) and Windows Server Preview, REDOSPECTOR uncovers 19 vulnerabilities in core services (including MSMQ, Remote Desktop Gateway, and CDP), leading to 12 assigned CVEs. Microsoft confirmed seven pre-authentication DoS issues in CDP and performed architectural adjustments, demonstrating that REDOSPECTOR can expose resource-mismanagement flaws that evade conventional fuzzing.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper19

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖