Using ALPC security features to compromise RPC services

WanJunJie Zhang, Yisheng He

DEF CON 32 Main Stage · Day 1 · Main Stage

Overview

In this DEF CON 32 talk, security researcher WanJunJie Zhang, from Hillstone Networks, delved into the intricacies of inter-process communication mechanisms within the Windows operating system, specifically Lightweight Procedure Call (LPC) and Remote Procedure Call (RPC). The presentation aimed to shed light on their shared architecture, common vulnerabilities, and critically, how novel security flaws can be exploited to bypass robust Windows security mitigations such as Address Space Layout Randomization (ASLR), Data Execution Prevention (DEP), and Control Flow Guard (XFG), ultimately leading to a system shell.

Watch on YouTube

Visual summary for Using ALPC security features to compromise RPC services by WanJunJie Zhang, Yisheng He
Visual summary for Using ALPC security features to compromise RPC services by WanJunJie Zhang, Yisheng He

Key moments

  1. 0:00 Speaker introduction and talk agenda overview
  2. 1:15 Details of novel vulnerabilities bypassing security mitigations
  3. 2:00 LPC/RPC architecture and huge attack surface
  4. 2:27 Reasons for combining LPC and RPC analysis
  5. 3:00 Efficient data passing via shared memory sections

Using ALPC security features to compromise RPC services

Speakers: WanJunJie Zhang, Security Researcher, Hillstone Networks; Yisheng He

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=Eyl_0YxfnpQ

Overview

In this DEF CON 32 talk, security researcher WanJunJie Zhang, from Hillstone Networks, delved into the intricacies of inter-process communication mechanisms within the Windows operating system, specifically Lightweight Procedure Call (LPC) and Remote Procedure Call (RPC). The presentation aimed to shed light on their shared architecture, common vulnerabilities, and critically, how novel security flaws can be exploited to bypass robust Windows security mitigations such as Address Space Layout Randomization (ASLR), Data Execution Prevention (DEP), and Control Flow Guard (XFG), ultimately leading to a system shell.

Zhang's research focuses on uncovering vulnerabilities in both user-mode and kernel-mode components of Windows, a testament to his expertise recognized by Microsoft, which has listed him as a Most Valuable Researcher (MVR) for multiple consecutive years. The talk underscored the significant attack surface presented by LPC and RPC, which are fundamental to the operation of countless Windows system services. By dissecting their underlying mechanisms, Zhang sought to demonstrate that even seemingly minor security flaws can have profound implications, enabling attackers to circumvent modern security defenses designed to prevent privilege escalation and arbitrary code execution.

The core premise of the presentation revolved around the idea that despite the critical role these communication protocols play and the layers of security built around them, subtle vulnerabilities can still be leveraged for high-impact attacks. The speaker promised to reveal details of vulnerabilities discovered by his team that exploit the shared security mechanisms of LPC and RPC, culminating in a step-by-step demonstration of achieving a system shell. This research is crucial for both offensive security practitioners seeking to understand new attack vectors and defensive teams striving to harden Windows environments against sophisticated threats.

Background

▶ Watch: Speaker introduction and talk agenda overview (0:00)

The Windows operating system relies heavily on robust inter-process communication (IPC) mechanisms to allow different components and services to interact securely and efficiently. Two foundational technologies in this space are Lightweight Procedure Call (LPC) and Remote Procedure Call (RPC). LPC was introduced to provide a more lightweight and efficient alternative to RPC for communication between processes on the same machine, particularly within core Windows system services. Its design prioritizes speed and efficiency, making it ubiquitous across the operating system's internal workings.

The speaker highlights a critical architectural overlap: most RPC services within Windows are built upon either LPC or named pipes. This fundamental dependency means that LPC and RPC often share the same underlying security mechanisms and, consequently, a common attack surface. A security flaw discovered within LPC, for instance, can directly impact the security posture of numerous RPC services that rely on it. This interconnectedness makes a holistic understanding of both protocols essential for vulnerability research and system hardening.

RPC, as described from the perspective of Windows internals, supports various communication modules, including message queries and shared sections. The latter, shared section objects, are particularly emphasized for their efficiency in data passing. Unlike traditional message passing which might involve copying data between process address spaces, shared sections allow processes to map a common memory region into their respective address spaces, enabling direct and fast data exchange. This efficiency, however, introduces specific security considerations regarding memory management and access control.

Within a shared section, memory can be further subdivided into regions. A region represents a specific range of shared memory that can be opened within the context of a given port. The access control for these sections and regions is crucial: typically, the server process might have broader shared access, while a client process might be granted only write access to specific parts of the shared memory. This controlled access is intended to prevent unauthorized data manipulation but, as the talk hints, can become a vector for exploitation if not perfectly implemented. The architecture of splitting a section into multiple regions, each defined by an offset and size, is designed to manage shared memory granularly, but also presents opportunities for boundary conditions and logical errors if not handled with extreme care.

Key Findings

▶ Watch: Details of novel vulnerabilities bypassing security mitigations (1:15)

The central promise of this talk, as outlined by WanJunJie Zhang, is the discovery of novel vulnerabilities within the intertwined LPC and RPC security mechanisms that possess the capability to bypass several critical Windows security mitigations. Specifically, the research claims to demonstrate how a "small security flaw" can be leveraged to circumvent Address Space Layout Randomization (ASLR), Data Execution Prevention (DEP), and Control Flow Guard (XFG). The ultimate objective of these bypasses is to achieve a system shell, indicating a full privilege escalation to the highest possible authority on a Windows system.

While the provided transcript primarily focuses on architectural background and historical vulnerability patterns, the speaker explicitly states that they will present the "details of the vulnerabilities I found by myself and my team." The significance of this claim lies in the fact that ASLR, DEP, and XFG are core pillars of modern operating system security, designed to make exploitation significantly more difficult, if not impossible, for many classes of vulnerabilities. Bypassing these simultaneously with a single, seemingly minor flaw would represent a substantial advancement in offensive techniques against Windows, highlighting a fundamental weakness in how LPC/RPC security features are implemented or interact. The core finding, therefore, is the potential existence and exploitability of such a flaw, which could lead to arbitrary code execution with SYSTEM privileges, effectively neutralizing the effectiveness of these robust mitigations.

Technical Deep Dive

▶ Watch: LPC/RPC architecture and huge attack surface (2:00)

The technical foundation of this research lies in a comprehensive understanding of how LPC and RPC operate within the Windows environment, particularly their shared architectural elements and data passing mechanisms. LPC (Lightweight Procedure Call) and RPC (Remote Procedure Call) are both integral to inter-process communication, with LPC serving as a highly optimized, local IPC mechanism predominantly used by Windows system services. RPC, while capable of network communication, frequently leverages LPC or named pipes for local IPC, creating a convergent attack surface. This architectural dependency means that a vulnerability in the lower-level LPC mechanism can directly expose higher-level RPC services to compromise.

Data transfer between processes using RPC often employs message queries or, for greater efficiency, shared section objects. Shared sections are a more performant method because they allow a segment of physical memory to be mapped into the virtual address spaces of multiple processes. This eliminates the need for expensive data copying operations, enabling direct access to shared data. From a security perspective, however, this efficiency necessitates rigorous access control and careful management of memory regions.

A section object in Windows represents a block of memory that can be shared between processes. Within a section object, memory can be logically divided into regions. Each region is defined by a specific map offset and size, allowing for granular control over which parts of the shared memory are accessible. The speaker notes that in a typical client-server interaction involving shared sections, the server process might have full shared access, while the client process is often restricted to write access only. This design is intended to prevent clients from reading sensitive server data or executing arbitrary code from shared memory. However, precisely these access control distinctions and memory mapping operations can become sources of vulnerabilities if not handled with absolute precision. Errors in calculating offsets, sizes, or managing memory permissions within these regions could lead to out-of-bounds writes, information disclosure, or other memory corruption issues.

Beyond the architectural specifics, the talk also touched upon historical vulnerabilities, providing context for the speaker's current research. A common class of logical bugs in RPC services arises during file operations, particularly when the service attempts to impersonate the calling client's security token. This impersonation allows the service, which typically runs with higher privileges (e.g., SYSTEM), to perform file operations on behalf of the less privileged client. The vulnerability often manifests when the service fails to properly handle file paths that incorporate symbolic links (or junction points, hard links, etc.). An attacker, as a low-privileged client, can craft a symbolic link that points from a location they control to a sensitive system file or directory. When the RPC service, impersonating the client, performs an operation (like writing, modifying, or deleting a file) on what it believes is a benign path, it inadvertently follows the symbolic link. Because the service is executing with its own elevated privileges, it can then perform unauthorized actions on critical system files that the client would normally have no access to. This is a classic privilege escalation technique that exploits a logical flaw in path canonicalization and privilege separation during file I/O operations.

The speaker's team claims to have discovered new vulnerabilities that can bypass modern security mitigations like ASLR, DEP, and XFG. While the specific technical details of these new vulnerabilities were not elaborated upon in the provided transcript, understanding these mitigations is crucial to appreciating the significance of their bypass.

  • ASLR (Address Space Layout Randomization): This mitigation randomizes the memory addresses of key executables and libraries (like DLLs) in a process's address space. This makes it harder for attackers to predict the location of specific functions or data structures, a prerequisite for many exploitation techniques such as Return-Oriented Programming (ROP).
  • DEP (Data Execution Prevention): DEP marks memory pages as either executable or non-executable. It prevents code from running in data-only memory regions (like the stack or heap), thereby thwarting attacks that attempt to inject and execute malicious code in data buffers.
  • XFG (Control Flow Guard): XFG is a control flow integrity (CFI) mitigation that verifies indirect calls and jumps target valid code locations. It helps prevent attackers from redirecting program execution to arbitrary code by corrupting function pointers or return addresses, even if they manage to bypass ASLR.

The assertion that a "small security flaw" in LPC/RPC can bypass these three robust mitigations simultaneously suggests a deep understanding of their internal workings and potential blind spots. Such a flaw might involve a primitive that allows for arbitrary read/write capabilities, potentially within kernel memory or a highly privileged user-mode process, which could then be used to leak ASLR offsets, mark data pages as executable, or disable XFG checks. The specific mechanism, whether it's a type confusion, an uninitialized variable, an integer overflow leading to memory corruption, or a logical bypass of an access check, remains a critical but unrevealed detail of the talk. However, the architectural foundation laid out for LPC/RPC, particularly the complexities of shared memory and region management, points towards potential areas where such subtle flaws could reside.

Demo / Proof of Concept

▶ Watch: Reasons for combining LPC and RPC analysis (2:27)

The speaker explicitly stated in the agenda that they would "show you step by step to use this small security flaw to bypass the security mitigations like ASLR DEP XFG and finally get system shell." This indicates that a live demonstration or a detailed walkthrough of a Proof of Concept (PoC) exploit was planned as a core component of the talk. The objective of this demonstration would have been to concretely illustrate the exploit chain, starting from the initial "small security flaw" within the LPC/RPC security mechanism, through the bypass of ASLR, DEP, and XFG, and culminating in the acquisition of a system shell. Such a demonstration would typically involve showing the attacker's low-privileged process interacting with a vulnerable RPC service, triggering the flaw, elevating privileges, and then executing a command prompt or other arbitrary code with SYSTEM authority. Unfortunately, the provided transcript content, being very brief and introductory, does not contain any details regarding this planned demonstration or the specifics of the PoC exploit. Therefore, while a demo was clearly intended and promised, its mechanics and outcomes are not available in this segment of the talk.

Defensive Implications

▶ Watch: Efficient data passing via shared memory sections (3:00)

The findings and discussions presented in this talk, particularly concerning vulnerabilities within LPC/RPC and the potential to bypass modern mitigations, carry significant implications for defenders. Understanding these attack vectors is paramount for hardening Windows systems against sophisticated privilege escalation attacks.

Firstly, the emphasis on logical bugs in file operations involving symbolic links serves as a critical reminder. Defenders must ensure that any service performing file I/O operations, especially those that impersonate client tokens or run with elevated privileges, implements robust path validation and canonicalization. Services should never implicitly trust user-supplied paths. Instead, they should:

  • Canonicalize paths: Resolve all symbolic links, junction points, and relative paths to their absolute, real file system locations before performing any operations.
  • Validate access: Explicitly check if the impersonated client token truly has the necessary permissions for the canonicalized target path, rather than relying solely on the service's own elevated privileges.
  • Restrict privileges: Services should always operate with the least privileges necessary. If a service needs to perform privileged file operations, it should do so in a highly constrained manner, potentially by dropping privileges immediately after the critical operation or by delegating to a dedicated, sandboxed helper process.
  • Monitor file system events: Implement logging and monitoring for suspicious file system activities, particularly those involving symbolic links created by low-privileged users that point to sensitive system locations.

Secondly, the claimed ability to bypass ASLR, DEP, and XFG through a "small security flaw" in LPC/RPC highlights a potential blind spot in current Windows security architecture. While the specifics of these bypasses were not detailed, the general implication is that current mitigation strategies might not be entirely foolproof against certain classes of vulnerabilities in core IPC mechanisms. For defenders, this means:

  • Patching is paramount: Stay vigilant for security updates from Microsoft related to LPC, RPC, and associated system services. These patches often address the very types of subtle flaws that could lead to mitigation bypasses.
  • Endpoint Detection and Response (EDR): Deploy and configure EDR solutions to detect anomalous process behavior, especially child processes spawned by system services, unexpected memory access patterns, or attempts to modify memory protection attributes. EDRs can often detect the effects of mitigation bypasses, even if the initial flaw is obscure.
  • Threat hunting: Proactively hunt for indicators of compromise (IOCs) related to LPC/RPC exploitation, such as unusual network connections originating from system services, modifications to critical system files, or unexpected administrative accounts being created.
  • Secure coding practices: For developers building Windows services, it reinforces the need for meticulous secure coding practices, especially when dealing with IPC, shared memory, and privilege management. Thorough security reviews and fuzzing of RPC interfaces are essential to uncover these subtle flaws before attackers do.
  • Application whitelisting: Implementing application whitelisting can restrict what executables can run on a system, making it harder for an attacker to execute arbitrary code even after achieving a system shell.

In conclusion, the talk serves as a potent reminder that fundamental Windows IPC mechanisms remain a fertile ground for sophisticated attackers. Defenders must move beyond generic security practices and focus on the specifics of how these critical components operate, diligently applying patches, strengthening validation logic, and employing advanced detection capabilities to counter these evolving threats.

Key Takeaways

  • LPC and RPC form a critical, shared attack surface: Many Windows RPC services are built upon LPC or named pipes, meaning vulnerabilities in one can compromise the other, affecting core system services.
  • Shared memory mechanisms introduce specific risks: The efficient section object and region data passing mechanisms in RPC, while performant, require precise access control and memory management to prevent flaws like out-of-bounds writes.
  • Logical bugs in file operations remain a threat: Historical vulnerabilities demonstrate how improper handling of symbolic links during privileged file operations can lead to privilege escalation by allowing services to operate on unauthorized files.
  • Novel vulnerabilities can bypass core Windows mitigations: The speaker claims to have found "small security flaws" in LPC/RPC that can bypass ASLR, DEP, and XFG, posing a significant challenge to modern Windows security.
  • Defenders must prioritize robust path validation and patching: To counter known and emerging threats, services performing file I/O must rigorously validate paths, and systems must be kept up-to-date with the latest security patches.
  • Advanced detection and response are crucial: EDR solutions and proactive threat hunting are vital for detecting the post-exploitation activities that follow successful mitigation bypasses and privilege escalation.

About the Speaker(s)

WanJunJie Zhang is a distinguished Security Researcher at Hillstone Networks. His primary research focus lies in identifying and analyzing vulnerabilities within the Windows operating system, encompassing both user-mode and kernel-mode components. Zhang's expertise and contributions to the security community have been recognized by Microsoft, which has honored him as a Most Valuable Researcher (MVR) for the years 2020, 2022, 2023, and 2024. His work significantly contributes to understanding and mitigating complex security threats in the Windows ecosystem. The talk also mentions a co-colleague, Yisheng He, who contributed to the research, though specific biographical details for He were not provided in the transcript.

Reviews

Heather Calloway (CISO) — MUST SEE

This talk presents a critical examination of Windows inter-process communication mechanisms, specifically LPC and RPC, claiming to identify novel vulnerabilities that can bypass core security mitigations like ASLR, DEP, and XFG to achieve a system shell. The implications for any organization operating Windows environments are profound, challenging fundamental assumptions about platform security and demanding immediate attention to patching strategies, robust path validation, and advanced detection capabilities. This isn't just a technical deep dive; it's a direct challenge to a CISO's understanding of their enterprise's risk posture.

→ Top-rated talks at DEF CON 32 Main Stage

All talks from DEF CON 32 Main Stage