A Heap Manipulation Diversity Fuzzing Method for Spatial Heap Vulnerabilities Exploitation

Runhao Li, Bin Zhang, Tao Wang, Chaojing Tang · 2023

Spatial heap vulnerabilities represent a significant aspect of memory corruptions, bringing serious threats to software security. To automatically exploit a spatial heap vulnerability, heap manipulation is required, which entails placing a victim object into target memory area to achieve control flow hijacking. Traditional fuzzers, which primarily rely on code coverage as a metric, are inadequate for discovering diverse exploitable heap states. In this paper, we propose a novel fuzzing technique that utilizes heap manipulation diversity as principle to explore various exploitable heap states. We implemented our prototype, HMFuzz, and the evaluation shows that it effectively transforms a Proof of Concept (PoC) into multiple exploitable PoCs. In our tests involving 6 bugs across 3 general-purpose programs, HMFuzz discovered an average of 35.3 exploitable PoCs per bug, thereby promoting further automatic exploit generation.

Read the paper · More papers on PaperTik