A critical vulnerability in Windows Heap management demonstrates how improper handling of record size fields allows arbitrary memory reads and writes. Suraj Malhotra presented a detailed exploitation technique that leverages the Low Fragmentation Heap (LFH) to achieve code execution on Windows systems.
See also: Windows 10: Free security updates in Europe

The Windows NT Heap operates through the FrontEnd and BackEnd. The FrontEnd allocator handles small allocations under 16KB using LFH, while the BackEnd allocator handles larger requests. Activating LFH requires 18 consecutive allocations of similar size, creating predictable memory layouts that can be exploited by attackers. The vulnerability manifests itself in applications that use private Heaps created via the ΗeapCreate().
These environments offer reduced mitigations compared to the default process heaps accessed via GetProcessHeap(). The core vulnerability exists in the record update functionality, where applications reuse previous record sizes when reading new data.
The exploit begins by enabling LFH via repeated allocations and then creating controlled memory layouts. Attackers manipulate the target->size, which remains unchanged across updates, allowing Heap Overflow conditions when new data exceeds allocated boundaries.
See also: Windows 11 gets video wallpaper feature

Suraj Malhotra demonstrates arbitrary read capabilities by filling UserBlocks via LFH activation, creating memory gaps via write removal, and reusing chunks with constructed data structures. This approach allows reading of sensitive memory areas, including base Heap addresses, ntdll base locations, and Process Environment Block (PEB) structures .
For arbitrary writes, attackers exploit Windows chunk structures that contain FLink and BLink to free chunks. By constructing fake chunks and manipulating freelist pointers, the researchers were able to exploit the FILE structure that contains crafted FILE objects with controlled _base, _file, _flag , and _bufsiz.
Exploiting the FILE structure requires specific flag combinations, including _IOBUFFER_USER (0x0080) and _IOALLOCATED (0x2000), to bypass validation checks. Setting _base to target memory addresses and _file to stdin allows arbitrary data to be written to controlled locations. The final exploit involves constructing Return-Oriented Programming (ROP) that use Windows APIs, such as ReadFile, VirtualProtect , and WriteFile, to load and execute shellcode. The technique leverages Microsoft's x64 calling convention, passing arguments through the RCX, RDX, R8, and R9 registers using ROP gadgets in ntdll.
See also: Hackers bypass Windows MoTW files with LNK Stomping

This vulnerability analysis, demonstrated through the “dadadb” challenge from Hitcon 2019, highlights the continued importance of proper heap management and size validation. Organizations should implement strong input validation, use modern heap implementations, and implement comprehensive memory protection mechanisms to mitigate sophisticated exploitation techniques targeting Windows heap internals.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
