Kill Latest MPU-based Protections in Just One Shot: Targeting All Commodity RTOSes

No ratings

Presented at BlackHat USA 2023 by

The security of numerous commodity RTOSes has been significantly improved since the pandemic. Features such as privilege isolation, MPU support, and DEP are now available across a broad range of devices. However, does this imply that these protection-enabled RTOSes are immune to exploitation?In this talk, we will present severe security flaws that are universally present in the latest protections of commodity RTOSes, including Amazon's FreeRTOS, ARM's MbedOS, Microsoft's Azure ThreadX, Samsung's TizenRT, and rt-thread. These flaws encompass MPU misconfiguration, the absence of permission checks during mode switching, and more. We will describe our exploitation technique that takes advantage of these security flaws to easily escalate privilege and achieve arbitrary read and write. Through live-demos, we will showcase such exploitation targetting real-world products. Given that similar security flaws can also exist in other RTOSes beyond those we analyzed, we will offer recommendations for temporarily patching these flaws, followed by the release of a more mature mitigation design. We strongly encourage all related vendors to thoroughly investigate their products internally and address these security flaws as promptly as possible.