logo

corCTF 2023 smm-diary: Ropping in Ring -2

ID: 34cac68d-64e0-5e89-ac15-83c4e54127d1

STIX ID: report--34cac68d-64e0-5e89-ac15-83c4e54127d1

Feed Name: Will's Root

Threat Score
70/100

Date Published: 2023-08-03

Date Updated: 2026-04-19

Author: Unknown

...
...

This write-up documents a high-privilege System Management Mode (SMM) vulnerability in an OVMF module used in corCTF 2023 where an unchecked communication buffer pointer allows an arbitrary write from ring 0 into SMRAM. The author analyzes the bug, shows the vulnerable patched module source, explains how to trigger the SMI from kernel space (using ioremap and writing to port 0xB2/0xB3), and provides a kernel driver exploit that ROPs ring -2 to dump a flag from SMRAM.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.