Kill netscape.security.PrivilegeManager.enablePrivilege
Categories
(Firefox :: Security, task, P2)
Tracking
()
People
(Reporter: freddy, Unassigned)
References
Details
(Keywords: sec-want)
We should kill netscape.security.PrivilegeManager.enablePrivilege.
Common exploits for security bugs usually use a memory safety issue to build a arbitrary memory read/write privilege. With this privilege, attackers can overwrite prefs or static variables to gain system principal with netscape.security.PrivilegeManager.enablePrivilege.
Example:
The exploit at https://github.com/0vercl0k/CVE-2019-11708/blob/1cdf26140f17de8a620e90f4f6ea3865e18e49ad/ff-toolbox.js#L653-L680 is using a memory corruption bug to get arbitrary read/write .
- overwrites prefs so that IsInAutomation at https://searchfox.org/mozilla-central/rev/d24696b5abaf9fb75f7985952eab50d5f4ed52ac/dom/base/nsGlobalWindowOuter.cpp#1732 returns true
- this gives access to `netscape.security.PrivilegeManager.enablePrivilege(); which then gives system principal to the current document
IsInAutomationalso disallows remote network connections, so the exploit finds the InitiateSocket function and overwrites the check that disallows network connections (https://github.com/0vercl0k/CVE-2019-11708/blob/1cdf26140f17de8a620e90f4f6ea3865e18e49ad/cthulhu.js#L530-L611)
Updated•6 years ago
|
| Reporter | ||
Updated•6 years ago
|
Comment 1•6 years ago
|
||
I don't know if you want to link them to public bugs, but there's been a lot of prior work in this category. Bug 1448967 is about removing it entirely, and it depends on bug 462483 for removing it from Mochitests (maybe that can be fixed now?) and bug 1435113 for removing it from Talos. I started on the latter, but I stalled out on it. I think :emk has done the most recent hardening work on enablePrivilege.
Comment 2•6 years ago
|
||
(The latter two bugs have some relevant open bugs, of course.)
Updated•6 years ago
|
Comment 3•6 years ago
|
||
Of course we should nuke enablePrivilege from orbit, but I'm not sure what is the problem here. If the attacker can use exploits like CVE-2019-11708 to execute arbitrary code such as arbitrary read/write, we already lose the battle.
| Reporter | ||
Comment 4•6 years ago
|
||
(In reply to Masatoshi Kimura [:emk] from comment #3)
Of course we should nuke
enablePrivilegefrom orbit, but I'm not sure what is the problem here. If the attacker can use exploits like CVE-2019-11708 to execute arbitrary code such as arbitrary read/write, we already lose the battle.
Yes. This is about killing simple exploit chains.
The goal is to increase the amount of work required to go from memory safety issue and arbitrary read/write to full compromise for upcoming security issues. Enabling privileged "chrome" JavaScript execution shouldn't be as simple as flipping a byte.
Comment 5•6 years ago
|
||
I have removed enablePrivilege .
Updated•2 years ago
|
Description
•