Manipulating Shim and Office for Code Injection

Ron Ben-Yizhak, David Shandalov

DEF CON 32 Main Stage · Day 1 · Main Stage

Overview

This talk, "Shimmy What You Got: Manipulating Shim and Office for Code Injection," delivered by Ron Ben-Yizhak and David Shandalov of Deep Instinct, delves into novel methods for achieving code injection and privilege escalation on Windows systems. The researchers meticulously explored the often-overlooked Windows Application Compatibility Framework and its interaction with Microsoft Office, a ubiquitous and complex software suite. Their work unveils previously undocumented Remote Procedure Call (RPC) methods within Office's Click-to-Run service that facilitate arbitrary DLL injection.

Watch on YouTube

Visual summary for Manipulating Shim and Office for Code Injection by Ron Ben-Yizhak, David Shandalov
Visual summary for Manipulating Shim and Office for Code Injection by Ron Ben-Yizhak, David Shandalov

Key moments

  1. 0:00 Talk overview and research agenda
  2. 1:06 Understanding Windows App Compatibility Framework
  3. 3:20 Why Office: A complex target for research
  4. 4:00 Finding an exploitable RPC server in Office
  5. 5:15 Tracing RPC calls to WriteProcessMemory for injection
  6. 7:50 Achieving system privileges using Task Scheduler
  7. 8:20 New DLL injection technique and detection bypass implications

Manipulating Shim and Office for Code Injection

Speakers: Ron Ben-Yizhak, Security Researcher, Deep Instinct; David Shandalov, Security Researcher, Deep Instinct

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=-Z34ya4rb8A

Overview

This talk, "Shimmy What You Got: Manipulating Shim and Office for Code Injection," delivered by Ron Ben-Yizhak and David Shandalov of Deep Instinct, delves into novel methods for achieving code injection and privilege escalation on Windows systems. The researchers meticulously explored the often-overlooked Windows Application Compatibility Framework and its interaction with Microsoft Office, a ubiquitous and complex software suite. Their work unveils previously undocumented Remote Procedure Call (RPC) methods within Office's Click-to-Run service that facilitate arbitrary DLL injection.

The significance of this research lies in its ability to leverage benign, trusted system components and applications—specifically Microsoft Office—to perform malicious actions. By identifying an RPC method within the Click-to-Run service, the speakers demonstrated how an attacker could force a legitimate Office process to inject a malicious DLL into another process, including those running with NT AUTHORITY\SYSTEM privileges. This approach presents a substantial challenge to traditional security products like Endpoint Detection and Response (EDR) solutions, which often whitelist or grant elevated trust to core operating system and widely used application processes.

Furthermore, the talk introduces a concept for a fileless technique to apply malicious shims, moving beyond conventional shim abuse that relies on registry modifications. This innovative angle re-examines an old attack vector, demonstrating its continued relevance and potential for sophisticated evasion. The findings collectively highlight the persistent security risks associated with legacy code, complex software architectures, and undocumented internal mechanisms within widely deployed systems, providing critical insights for both offensive and defensive security practitioners.

Background

▶ Watch: Talk overview and research agenda (0:00)

The foundation of this research lies within the Windows Application Compatibility Framework, a critical component of the operating system designed to ensure that older software can run smoothly on newer Windows versions. As operating systems evolve, changes in APIs, registry paths, or directory structures can break legacy applications. Microsoft addresses these issues through various compatibility modes, which involve API hooking, patching the application's assembly, and other runtime modifications to adapt the program's behavior.

At the heart of this mechanism are shim database files, or SDB files. These files contain the specific fixes and compatibility modes required by different applications. The primary SDB file, sysmain.sdb, is maintained by Microsoft and updated only through system updates. Users can inspect these files using Microsoft's Compatibility Administrator graphical tool, which reveals the specific compatibility modes applied to various applications (e.g., Age of Empires 3 requiring "High DPI aware"). Crucially for attackers, users can also install custom SDB files by writing them to specific registry paths.

The abuse of the shim framework is not a new concept. The speakers acknowledged that this has been an attack vector for many years, citing a DEF CON talk from nearly a decade prior that detailed how shims could be used for credential access, network redirection, and other malicious purposes. Additionally, security researcher Alex Ionescu published articles on the subject as far back as 2007. Due to its age, most modern security products are expected to detect malicious shim usage, typically by monitoring the registry paths where custom SDB files are installed.

Despite the known detection methods, Ron Ben-Yizhak and David Shandalov embarked on new research, initially aiming for an EDR bypass or even disabling EDRs. When this proved less fruitful, they shifted their focus to attack surface research. Their chosen target was Microsoft Office, a ubiquitous software suite found on virtually every Windows machine. Office's complexity, encompassing COM objects, scripting engines, and cloud synchronization, presented a vast attack surface. Most importantly, Office's extensive backwards compatibility, spanning over 30 years, meant it contained a significant amount of legacy code—a prime target for uncovering vulnerabilities or undocumented behaviors that could be exploited. This combination of widespread deployment, intricate architecture, and historical codebases made Office an ideal candidate for deep security research.

Key Findings

▶ Watch: Why Office: A complex target for research (3:20)

The research yielded several significant findings, demonstrating novel techniques for code injection and privilege escalation by exploiting the Windows Application Compatibility Framework and Microsoft Office components.

First, the speakers discovered an undocumented Remote Procedure Call (RPC) method within the Click-to-Run SVC service, a core component of Microsoft Office. This method, located within virtualization.dll and subsystem controller.dll, was found to perform arbitrary DLL injection. This discovery is critical because it allows an attacker to leverage a legitimate, highly trusted Office service to load and execute arbitrary code within other processes, potentially bypassing security controls that monitor for direct malicious injection attempts.

Second, the researchers successfully combined this RPC-triggered DLL injection with a method for privilege escalation. They identified that the Click-to-Run service, while powerful, initially performs injection using the calling client's security token due to RPC Impersonate Client. To elevate privileges, they devised a strategy to target processes launched by the Task Scheduler service that run with NT AUTHORITY\SYSTEM privileges and are initiated in a suspended state. By injecting their malicious DLL into such a suspended, system-level process (e.g., "Office automatic updates 2.0"), they could achieve system-level code execution from an administrative context. This multi-stage attack chain allows for a potent combination of code injection and privilege escalation using benign application components.

Finally, the talk highlighted the discovery of a novel fileless technique to apply a malicious shim on a process. While the detailed technical implementation of this specific technique was not fully elaborated in the provided transcript, the speakers mentioned that its discovery involved a comprehensive reverse engineering process of the app compatibility driver and its undocumented internal structures. This finding is particularly impactful as it challenges conventional detection methods for shim abuse, which typically rely on monitoring specific registry paths. A fileless approach would circumvent these traditional defenses, making detection significantly more difficult for EDRs and other security products. This represents a significant advancement in shim-based attack vectors, moving beyond the "old attack vector" status into a more sophisticated and evasive realm.

Technical Deep Dive

▶ Watch: Finding an exploitable RPC server in Office (4:00)

The technical journey began with the selection of Microsoft Office as the primary target for attack surface research. The researchers focused on the Click-to-Run SVC service, known for its role in Office's installation, updates, and virtualization capabilities. Their initial step was to enumerate the RPC interfaces exposed by this service. This investigation narrowed down the relevant files to Office Click-to-Run.exe, virtualization.dll, and subsystem controller.dll.

During their analysis of virtualization.dll, a peculiar string caught their attention: "Could not inject subsystem DLL to child process." This string was a strong indicator of DLL injection functionality. Further investigation confirmed that the function utilizing this string was exposed via RPC, meaning it could be invoked remotely. To validate this, the researchers debugged the Office service, setting breakpoints on common API calls used for code injection. Upon launching Microsoft Word, they observed the service making calls to WriteProcessMemory, confirming the presence of a legitimate, internal DLL injection mechanism. The call stack revealed that the RPC call traversed several undocumented functions across multiple DLLs before reaching WriteProcessMemory. The virtualization.dll itself is described as the "Microsoft application virtualization client virtualization manager component," underscoring its role in managing virtualized application environments. This DLL was found to expose two undocumented RPC methods.

To gain more insight into these undocumented functions, the researchers employed PowerShell to identify RPC clients interacting with the Click-to-Run SVC. This led them to Subsystem64.dll, a file that, unlike the others, contained symbols. Analyzing Subsystem64.dll revealed two key client functions: NotifyNewProcess and NotifyNewChildProcess. While NotifyNewProcess did not yield interesting results, NotifyNewChildProcess was directly responsible for triggering the server-side WriteProcessMemory calls. The comprehensive call stack showed that during CreateProcessInternal, functions related to the app compatibility framework were invoked, followed by the opening of the shim database. This confirmed the tight integration between Office's virtualization components and the core Windows compatibility mechanisms.

A critical challenge identified early in the research was the privilege context of the injection. Although the Click-to-Run SVC runs with NT AUTHORITY\SYSTEM privileges, the RPC server thread that handles client requests performs RPC Impersonate Client. This means the injection initially occurs using the client's security token, preventing immediate privilege escalation to SYSTEM. To overcome this, the researchers needed a way to inject into a process already running at a higher privilege level, specifically SYSTEM.

Their solution involved targeting processes launched by the Task Scheduler service. Task Scheduler is a prime candidate because many default tasks are configured to run with SYSTEM privileges, and some are even related to Office, such as "Office automatic updates 2.0." The key insight was to identify SYSTEM-privileged processes that are launched in a suspended state. Injecting a DLL into a suspended process allows for modifications to its Import Address Table (IAT) or memory space before the process fully initializes and executes its legitimate code. This ensures the malicious DLL is loaded and executed early in the process lifecycle, achieving the desired code execution with elevated privileges. The strategy of using an Office-related scheduled task for injection further reduces suspicion, as the Office Click-to-Run.exe service would be seen injecting a DLL into another Office-related process.

Beyond the Office RPC injection, the researchers also highlighted a separate, novel attack vector: a fileless technique to apply a malicious shim. This involved a deep reverse engineering process of the app compatibility driver and its undocumented internal structures. While the specific technical details of how this fileless shim is applied were not elaborated in the provided transcript, its discovery signifies a significant evolution in shim abuse. Traditional shim attacks rely on installing SDB files via registry entries, which are easily monitored. A fileless method would bypass these established detection mechanisms, potentially allowing for highly stealthy and persistent code execution or manipulation of application behavior without leaving easily traceable disk artifacts. This points to a deeper understanding of the kernel-level components governing application compatibility.

Demo / Proof of Concept

▶ Watch: Achieving system privileges using Task Scheduler (7:50)

While the talk's transcript does not provide a step-by-step walkthrough of a live demonstration, the speakers clearly articulated the successful execution and outcome of their attack chain. They described how, by leveraging the identified RPC method within the Office Click-to-Run SVC and targeting a suspended, system-level process, they were able to achieve DLL injection and privilege escalation.

Specifically, the researchers stated that the Office C2R client loaded our DLL, and that they "gained the console with the privileges of NT authority system." This outcome demonstrates a successful proof of concept where an administrative user could force a legitimate Office service to inject a malicious DLL into a process running as NT AUTHORITY\SYSTEM, thereby achieving the highest level of privilege on a Windows machine. The focus of the presentation was on the discovery and the underlying mechanisms, providing sufficient detail to convey the feasibility and impact of these sophisticated attack techniques.

Defensive Implications

▶ Watch: New DLL injection technique and detection bypass implications (8:20)

The findings presented in "Manipulating Shim and Office for Code Injection" carry significant defensive implications for organizations and security product vendors. The primary takeaway is that relying solely on reputation or traditional monitoring for known malicious behaviors is insufficient against sophisticated attacks leveraging trusted applications and system components.

  1. Enhanced RPC Monitoring for Office Services: Defenders should implement robust monitoring for RPC calls directed at the Office Click-to-Run SVC and its associated DLLs, specifically virtualization.dll and subsystem controller.dll. Unusual call patterns, unexpected parameters, or calls originating from non-standard processes could indicate an attack.
  2. Behavioral Analysis of Office Click-to-Run.exe: Security products must elevate their behavioral analysis capabilities to scrutinize actions taken by Office Click-to-Run.exe. Specifically, monitoring for instances where this executable performs WriteProcessMemory calls or other DLL injection techniques into other processes, particularly those running with NT AUTHORITY\SYSTEM privileges or those launched by the Task Scheduler service, is crucial. Such behavior from a typically benign process should be flagged as highly suspicious.
  3. Advanced Shim Detection: The discovery of a fileless technique to apply malicious shims necessitates a re-evaluation of current shim detection strategies. Simply monitoring registry paths for custom SDB files is no longer sufficient. Defenders need to explore more advanced techniques, potentially involving kernel-level monitoring for direct manipulation of the app compatibility framework's internal structures or driver interactions. This may require deeper inspection of loaded modules and their origins, as well as behavioral analysis of processes that interact with the compatibility engine.
  4. Suspended Process Monitoring: Organizations should pay close attention to processes launched in a suspended state, especially those configured to run as NT AUTHORITY\SYSTEM. Any attempt to inject code or modify the memory of such processes before they fully initialize should be considered a critical alert.
  5. EDR Evasion Awareness: The research explicitly aimed at EDR bypass. This underscores the need for EDR solutions to move beyond signature-based detection and known malicious IOCs. They must develop more sophisticated heuristics and machine learning models capable of identifying anomalous behavior from trusted applications, even when those applications are being coerced into performing malicious actions.
  6. Supply Chain and Application Security: The reliance on legacy code and undocumented features within widely used software like Office highlights the importance of rigorous security audits for complex applications. While Microsoft maintains sysmain.sdb, the potential for abusing other internal, undocumented mechanisms remains.

By implementing these defensive strategies, organizations can bolster their defenses against the types of advanced code injection and privilege escalation techniques demonstrated in this talk, moving towards a more proactive and resilient security posture.

Key Takeaways

  • Undocumented RPC Abuse in Office: Microsoft Office's Click-to-Run SVC service contains undocumented RPC methods that can be leveraged for arbitrary DLL injection by manipulating virtualization.dll and subsystem controller.dll.
  • Privilege Escalation via Trusted Services: Combining this RPC-triggered injection with targeting suspended, SYSTEM-privileged processes (e.g., those launched by Task Scheduler like "Office automatic updates 2.0") allows for effective privilege escalation to NT AUTHORITY\SYSTEM.
  • Novel Fileless Shim Technique: A new fileless technique for applying malicious shims was discovered through reverse engineering the app compatibility driver, challenging traditional shim detection methods that rely on registry monitoring.
  • Legacy Code as Attack Surface: The extensive backwards compatibility and complex architecture of popular software like Microsoft Office provide a rich and often overlooked attack surface for security researchers and adversaries.
  • Evolving EDR Detection: Security products, particularly EDR solutions, must enhance their behavioral analysis capabilities to detect malicious actions originating from typically benign, trusted processes like Office components, moving beyond simple whitelisting.
  • Continued Research into Windows Internals: The talk underscores the value of ongoing research into undocumented Windows internals and legacy components, as these areas continue to harbor potential vulnerabilities and attack vectors.

About the Speaker(s)

Ron Ben-Yizhak is a security researcher at Deep Instinct. He is a returning speaker to DEF CON, having presented his research at the conference for the third consecutive year. His work focuses on uncovering novel attack techniques and vulnerabilities within complex systems.

David Shandalov is also a security researcher at Deep Instinct. This presentation marked his debut as a speaker at DEF CON. His contributions to the research demonstrate a keen ability to delve into Windows internals and discover sophisticated exploitation methods.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This talk presents two distinct, highly sophisticated attack vectors: an undocumented RPC method within Microsoft Office's Click-to-Run service for arbitrary DLL injection, and a novel fileless technique for applying malicious shims. Both methods achieve privilege escalation to NT AUTHORITY\SYSTEM and demonstrate significant EDR evasion capabilities by leveraging trusted system components. The research is deeply technical, original, and provides critical insights for both offensive and defensive security practitioners, making it a must-see for anyone serious about Windows internals.

Heather Calloway (CISO) — STRONG ACCEPT

This talk presents highly relevant research demonstrating a sophisticated pathway to SYSTEM-level compromise on Windows systems by leveraging undocumented RPC methods within Microsoft Office's Click-to-Run service and novel fileless shim injection. The findings expose critical blind spots in traditional EDR solutions and underscore the persistent risk posed by legacy code and complex, trusted applications in enterprise environments. It provides actionable intelligence for security leaders and defenders to recalibrate their detection and response strategies.

→ Top-rated talks at DEF CON 32 Main Stage

All talks from DEF CON 32 Main Stage