ITADN

Hooking NtMapViewOfSection causes a crash in the target process

#346Openayushgupta-aic 创建于 2025-04-16
bug
A
ayushgupta-aiccommented
I seem to be hitting an issue while trying to hook NtMapViewOfSection. It causes an exception in the target process Below is the output from WinDbg: ************* Preparing the environment for Debugger Extensions Gallery repositories ************** ExtensionRepository : Implicit UseExperimentalFeatureForNugetShare : true AllowNugetExeUpdate : true NonInteractiveNuget : true AllowNugetMSCredentialProviderInstall : true AllowParallelInitializationOfLocalRepositories : true EnableRedirectToV8JsProvider : false -- Configuring repositories ----> Repository : LocalInstalled, Enabled: true ----> Repository : UserExtensions, Enabled: true >>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.047 seconds ************* Waiting for Debugger Extensions Gallery to Initialize ************** >>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.016 seconds ----> Repository : UserExtensions, Enabled: true, Packages count: 0 ----> Repository : LocalInstalled, Enabled: true, Packages count: 29 Microsoft (R) Windows Debugger Version 10.0.26100.1 AMD64 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [E:\share\e\temp\Notepad.exe.7296.dmp] User Mini Dump File with Full Memory: Only application data is available ************* Path validation summary ************** Response Time (ms) Location Deferred srv*E:\Symbols*https://msdl.microsoft.com/download/symbols Symbol search path is: srv*E:\Symbols*https://msdl.microsoft.com/download/symbols Executable search path is: Windows 10 Version 26100 MP (2 procs) Free ARM 64-bit (AArch64) Product: WinNt, suite: SingleUserTS Edition build lab: 26100.1.arm64fre.ge_release.240331-1435 Debug session time: Mon Mar 31 20:22:00.000 2025 (UTC + 5:30) System Uptime: 0 days 0:12:27.208 Process Uptime: 0 days 0:00:04.000 ........ This dump file has an exception of interest stored in it. The stored exception information can be accessed via .ecxr. (1c80.1fa0): Access violation - code c0000005 (first/second chance not available) For analysis of this file, run !analyze -v ntdll!NtWaitForMultipleObjects+0x4: 00007ff8`bef815e4 d65f03c0 ret 0:000> kbn # RetAddr : Args to Child : Call Site 00 00007ff8`bf07be58 : 00000000`00000094 00000000`000000bc 00000000`00000000 ffff8b19`2ed703d0 : ntdll!NtWaitForMultipleObjects+0x4 01 00007ff8`bf07b154 : 00000000`00000094 00000000`000000bc 00000000`00000000 ffff8b19`2ed703d0 : ntdll!WerpWaitForCrashReporting+0xa8 02 00007ff8`bef8b5f4 : 00000000`00000098 00000000`000000a4 00000000`00000004 00000000`00000094 : ntdll!RtlReportExceptionHelper+0x21c 03 00007ff8`bf0d6ec8 : 000000a7`884fdb90 00007ff8`bf0d6ec8 00000000`00000000 000000a7`884ff4d0 : ntdll!RtlReportException+0x84 04 00007ff8`bf0e4480 : 000000a7`884ff3c0 00007ff8`bf0e4480 00000000`00000000 000000a7`883ab000 : ntdll!LdrpInitializeProcessWrapperFilter+0x60 05 00007ff8`bf0df118 : 000000a7`884fdc10 00007ff8`bf0df118 00000000`00000000 00007ff8`bf2c43d0 : ntdll!_LdrpInitialize$filt$0+0x14 06 00007ff8`bf06219c : 00000000`00000000 00007ff8`bf2c43d0 00007ff8`bf2c43d0 000000a7`884fdd00 : ntdll!_C_ExecuteExceptionFilter+0x38 07 00007ff8`bf0dee24 : 000000a7`884fdc80 00007ff8`bf0dee24 000000a7`884fe690 000000a7`884fe2e0 : ntdll!_C_specific_handler+0xbc 08 00007ff8`befc3900 : 000000a7`884fe280 00007ff8`befc3900 000000a7`884fdd00 00007ff8`bf0412bc : ntdll!RtlpExecuteHandlerForException+0x14 09 00007ff8`bf0dec80 : 00000000`00000000 00000000`00000000 000000a7`884fdcf0 00007ff8`00000000 : ntdll!RtlDispatchException+0x2e8 0a 00007ff8`bef81294 : 40001040`0040000f 00000000`00000000 ffffffff`ffffffff 00000256`a3107480 : ntdll!KiUserExceptionDispatch+0x40 0b 00007ff8`bf054e64 : 00000000`00800000 00000000`00000080 000000a7`884fea40 00007ff8`bf05444c : ntdll!NtMapViewOfSection+0x4 0c 00007ff8`bf05444c : 00000000`00800000 00000000`00000080 000000a7`884fea40 00007ff8`bf05444c : ntdll!LdrpMinimalMapModule+0x114 0d 00007ff8`bf053204 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!LdrpMapDllWithSectionHandle+0x54 0e 00007ff8`bf0527b0 : 000000a7`884feaf0 00007ff8`bf0527b0 00000000`00000060 00000000`00000000 : ntdll!LdrpLoadKnownDll+0x204 0f 00007ff8`bf0399a0 : 000000a7`884feb90 00007ff8`bf0399a0 00000000`00000000 000000a7`884fed90 : ntdll!LdrpFindOrPrepareLoadingModule+0x1f0 10 00007ff8`bf039620 : 000000a7`884fed50 00007ff8`bf039620 00000020`00000000 00000256`a3107450 : ntdll!LdrpLoadDllInternal+0x1e8 11 00007ff8`bf0378b8 : 00000000`00000000 00000000`00000000 00000020`00000000 00000000`01000018 : ntdll!LdrpLoadDll+0xd8 12 00007ff8`bf03d2c4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!LdrLoadDll+0x118 13 00007ff8`bf03f170 : 00000000`00000000 00007ff8`00000000 00000000`00000000 00000000`00000000 : ntdll!LdrpInitializeKernel32Functions+0xbc 14 00007ff8`bf0412c0 : 00007ff8`bf2fed10 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!LdrpInitializeProcess+0x16c8 15 00007ff8`bf03d164 : 000000a7`884ff430 00007ff8`bf03d164 00000000`00000000 00007ff8`bef80000 : ntdll!LdrpInitialize+0x1e0 16 00007ff8`bf03bff0 : 000000a7`884ff490 00007ff8`bf03bff0 00000000`00000000 00000000`00000001 : ntdll!LdrpInitializeInternal+0x19c 17 00007ff8`bf05bb98 : 000000a7`884ff4b0 00007ff8`bf05bb98 000000a7`884ff4d0 00000000`00000000 : ntdll!LdrpInitialize+0x30 18 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!LdrInitializeThunk+0x18 0:000> !analyze -v ******************************************************************************* * * * Exception Analysis * * * ******************************************************************************* KEY_VALUES_STRING: 1 Key : AV.Fault Value: Read Key : Analysis.CPU.mSec Value: 2592 Key : Analysis.DebugAnalysisManager Value: Create Key : Analysis.Elapsed.mSec Value: 3823 Key : Analysis.Init.CPU.mSec Value: 921 Key : Analysis.Init.Elapsed.mSec Value: 125725 Key : Analysis.Memory.CommitPeak.Mb Value: 115 Key : Timeline.OS.Boot.DeltaSec Value: 747 Key : Timeline.Process.Start.DeltaSec Value: 4 Key : WER.OS.Branch Value: ge_release Key : WER.OS.Timestamp Value: 2024-03-31T14:35:00Z Key : WER.OS.Version Value: 10.0.26100.1 Key : WER.Process.Version Value: 11.2501.30.0 NTGLOBALFLAG: 40000000 PROCESS_BAM_CURRENT_THROTTLED: 0 PROCESS_BAM_PREVIOUS_THROTTLED: 0 APPLICATION_VERIFIER_FLAGS: 0 CHKIMG_EXTENSION: !chkimg -lo 50 -d !ntdll 7ff8bef81290-7ff8bef8129b 12 bytes - ntdll!NtMapViewOfSection [ 01 05 00 d4 c0 03 5f d6:71 ff df f0 31 6e 41 f9 ] 7ff8bf276021-7ff8bf276023 3 bytes - ntdll!#__os_arm64x_direct_check_call$thunk$13264489571522593687+1 [ 4c ff 17:ac 04 14 ] 7ff8bf276030-7ff8bf276033 4 bytes - ntdll!#__os_arm64x_direct_check_icall$thunk$12647412828258631054 (+0x0f) [ e0 4c ff 17:e4 ac 04 14 ] 7ff8bf276040-7ff8bf276043 4 bytes - ntdll!#__os_arm64x_direct_check_icall_cfg$thunk$5088010202698591951 (+0x10) [ d8 4c ff 17:c0 ac 04 14 ] 7ff8bf276050-7ff8bf276051 2 bytes - ntdll!#memcmp$thunk$5082098375320128673 (+0x10) [ 9c 55:dc 5b ] 7ff8bf276060-7ff8bf276061 2 bytes - ntdll!#memcpy$thunk$5092507451902320735 (+0x10) [ 80 54:58 5b ] 7ff8bf276070-7ff8bf276071 2 bytes - ntdll!#memmove$thunk$1334101548148046726 (+0x10) [ 7c 54:54 5b ] 7ff8bf276080-7ff8bf276081 2 bytes - ntdll!#memset$thunk$14999732841581576469 (+0x10) [ b0 56:f8 5a ] 7ff8bf276090-7ff8bf276091 2 bytes - ntdll!#strlen$thunk$14608158609015117340 (+0x10) [ 3c 58:54 5c ] 7ff8bf2760a0-7ff8bf2760a3 4 bytes - ntdll!guard_check_icall$thunk$15021643654165956172 (+0x10) [ 2c a4 f9 17:08 ac 04 14 ] 7ff8bf2760b0-7ff8bf2760b1 2 bytes - ntdll!memcmp$thunk$10889394497538118122 (+0x10) [ 0c a5:2c aa ] 7ff8bf2760c1 - ntdll!memcpy$thunk$10901767301887916580+1 (+0x11) [ a4:a9 ] 7ff8bf2760d1 - ntdll!memmove$thunk$3342814547840089611+1 (+0x10) [ a4:a9 ] 7ff8bf2760e0-7ff8bf2760e1 2 bytes - ntdll!memset$thunk$772440563353939046 (+0x0f) [ 10 a6:70 a9 ] 7ff8bf2760f0-7ff8bf2760f1 2 bytes - ntdll!strlen$thunk$10150925376295766583 (+0x10) [ 4c a7:94 aa ] 7ff8bf320028-7ff8bf32002a 3 bytes - ntdll!_guard_dispatch_icall_fptr [ 60 f1 0d:40 11 3a ] 48 errors : !ntdll (7ff8bef81290-7ff8bf32002a) CONTEXT: (.ecxr) x0=0000000000000000 x1=ffffffffffffffff x2=00000256a3107480 x3=0000000000000000 x4=0000000000000000 x5=0000000000000000 x6=00000256a31073f8 x7=0000000000000001 x8=0000000000000000 x9=00000256a20a0000 x10=00007ff8bf2fea18 x11=00007ff8bf2fea18 x12=0000000000000012 x13=0000000000000000 x14=0000000000000000 x15=0000000000000000 x16=0000000000000000 x17=0000758e5978d650 x18=00000256a3107480 x19=0000000000000060 x20=00000256a3107450 x21=00000256a3107350 x22=0000000000000000 x23=0000000000000000 x24=0000000000000000 x25=0000000000800000 x26=0000000000000001 x27=000000a7883ab000 x28=0000000000000000 fp=000000a7884fe760 lr=00007ff8bf054e64 sp=000000a7884fe750 pc=00007ff8bef81294 psr=40001040 -Z-- EL0 ntdll!NtMapViewOfSection+0x4: 00007ff8`bef81294 f9416e31 ldr xip1,[xip1,#0x2D8] Resetting default scope EXCEPTION_RECORD: (.exr -1) ExceptionAddress: 00007ff8bef81294 (ntdll!NtMapViewOfSection+0x0000000000000004) ExceptionCode: c0000005 (Access violation) ExceptionFlags: 00000000 NumberParameters: 2 Parameter[0]: 0000000000000000 Parameter[1]: 0000758e5978d928 Attempt to read from address 0000758e5978d928 PROCESS_NAME: Notepad.exe READ_ADDRESS: 0000758e5978d928 ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s. EXCEPTION_CODE_STR: c0000005 EXCEPTION_PARAMETER1: 0000000000000000 EXCEPTION_PARAMETER2: 0000758e5978d928 ADDITIONAL_DEBUG_TEXT: Followup set based on attribute [Is_ChosenCrashFollowupThread] from Frame:[0] on thread:[PSEUDO_THREAD] STACK_TEXT: 00000000`00000000 00000000`00000000 memory_corruption!ntdll+0x0 STACK_COMMAND: ** Pseudo Context ** ManagedPseudo ** Value: ffffffff ** ; kb SYMBOL_NAME: memory_corruption!ntdll FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE_c0000005_memory_corruption!ntdll IMAGE_NAME: memory_corruption MODULE_NAME: memory_corruption OS_VERSION: 10.0.26100.1 BUILDLAB_STR: ge_release OSPLATFORM_TYPE: arm64 OSNAME: Windows 10 FAILURE_ID_HASH: {5d0576d7-9f33-3bd5-c7eb-aaa2bf23945f} Followup: MachineOwner ---------
0 条评论