Hunting for Blues – the WSL Plan 9 Protocol BSOD
ID: 5639032d-e6df-5a9e-8dc3-fac81bbe9fab
STIX ID: report--5639032d-e6df-5a9e-8dc3-fac81bbe9fab
Feed Name: McAfee Labs Blog
McAfee Labs analysed the Windows WSL Plan 9 (P9) protocol implementation and found that a malicious P9 server (by hijacking the "fsserver" AF_UNIX socket) can send malformed R-messages that the p9rdr.sys driver processes in kernel context, resulting in local denial-of-service (BSOD). The issue requires local presence or privileged actions to enable WSL/socket hijack, does not enable kernel code execution or privilege escalation, and Microsoft validated the findings with mitigations focused on preventing socket hijacking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
