These libraries, such as libc, are loaded by other processes, including the polyapp process, and because their memory addresses never change, they can be leveraged to bypass ASLR and execute the attacker’s payload.
“We create a ROP chain that will execute an arbitrary OS command via the system standard C library function,” Fewer said. “The accompanying Metasploit exploit modules source code details the entire ROP chain.”
VoIP phones are attractive targets
Attackers have increasingly targeted embedded devices inside enterprise networks in recent years because unlike laptops, workstations, and servers, these devices are not monitored by endpoint detection and response (EDR) products. As such, they provide perfect footholds inside corporate environments that allow attackers to remain undetected for long periods of time and attack other systems.