Vulnerability Details
| Attribute | Value |
|---|---|
| CWE | CWE-121 (Stack-based Buffer Overflow); CWE-290 (Authentication Bypass by Spoofing) |
| Affected component | saappsvc.exe (SecureAge Application Whitelisting Service) |
| Affected pipe | \\.\pipe\SecureAgeApplicationWhitelisting (NULL DACL) |
| Exception code | 0xC0000409 (STATUS_STACK_BUFFER_OVERRUN) |
| Fault offset | 0x87f6b in saappsvc.exe (within __report_gsfailure) |
| CVSS 3.1 vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| CVSS 3.1 score | 5.5 Medium |
| Versions confirmed | v10.9.3, v10.10.0 |
| Code execution / LPE | Not demonstrated; current confirmed impact is service denial of service. |
Root Cause
1. Identity Check Uses Attacker-Controlled PID
The cmd=4 handler at 0x14006C671 reads a process ID from the message body at offset
0x02 and calls OpenProcess on that PID to retrieve a token, which is then
compared against the TrustedAccount registry key. It does not call
GetNamedPipeClientToken to verify the actual pipe client. Any standard user can supply
the PID of a SYSTEM process (e.g., lsass.exe, which is queryable via
PROCESS_QUERY_LIMITED_INFORMATION) to pass this check, since SYSTEM is listed in
TrustedAccount.
2. Stack Buffer Overrun in sub_6A120
After identity verification, the handler passes attacker-controlled payload fields to
sub_6A120 (RVA 0x6A120), which writes processed payload data into a stack
buffer without sufficient bounds checking. The write corrupts the MSVC /GS stack cookie.
__security_check_cookie detects the corruption and __report_gsfailure
raises STATUS_STACK_BUFFER_OVERRUN, terminating the service process.
Call Chain
| Function | RVA | Role |
|---|---|---|
| cmd=4 handler | 0x6C671 | PID identity check; dispatches to processing function; frame 0xA70 bytes |
sub_6A120 | 0x6A120 | Overflowing function; unbounded write corrupts the /GS cookie |
sub_8AEF0 | 0x8AEF0 | Processing stub called by sub_6A120; writes into the overflowing buffer; no bounds check |
sub_80640 | 0x80640 | __security_check_cookie; CMP RAX vs global cookie; BND JNE to __report_gsfailure on mismatch |
__report_gsfailure | ~0x87E99 | Raises STATUS_STACK_BUFFER_OVERRUN (0xC0000409); terminates the process |
Proof-of-concept code was provided privately during coordinated disclosure and is intentionally not being released publicly.
Security Impact
saappsvc.exe terminates. Standard users cannot
restart the service (sc start SAAppSvc returns Access Denied, error 5). Administrator
intervention or system reboot is required.
saappctl.sys retains its in-memory enforcement state
after saappsvc.exe crashes. The kernel driver does not re-read
AppWhitelistingMode from the registry on service failure; previously-blocked binaries
remain blocked. The AppWhitelistingMode = 0 registry value reflects the crash state but
does not alter live kernel enforcement. CVSS I:N reflects this finding.
STATUS_STACK_BUFFER_OVERRUN. No code execution path was confirmed during testing.
CVSS C:N and I:N reflect this finding.
Proof of Concept
The finding was validated from a standard user account without administrator rights or custom executables. Proof-of-concept code was provided privately during coordinated disclosure and is intentionally not being released publicly.
Confirmed output (running as TESTING\test, standard user):
[+] Connected as: TESTING\test (standard user, no admin rights)
[*] Sending cmd=4 with lsass PID=1032 at offset 0x02 (0x300 bytes)...
Service status: Stopped
[+] CONFIRMED: saappsvc.exe is no longer running
[*] AppWhitelistingMode=0 in registry (reflects crash state; kernel enforcement unaffected)
[!] sc start SAAppSvc -> [SC] OpenService FAILED 5: Access is denied.
Remediation
- Pipe DACL: Apply an administrator-only or service-account-only DACL to
\\.\pipe\SecureAgeApplicationWhitelistingat pipe creation time. Standard users should not be able to connect. - Identity check: Replace the PID-from-message-body identity verification with
GetNamedPipeClientTokento obtain the actual pipe client's token. Attacker-supplied PID values in the message body must never be used for privilege or identity decisions. - Bounds checking: Add explicit length bounds to the payload processing function called by cmd=4 to prevent the stack overrun irrespective of any access control fix.