TGViewer
RESOLUTE ATTACK RESOLUTE ATTACK @resoluteattack · 6.1K subscribers
Post #773 3.05K

Forwarded from Private Shizo

💥CVE-2023-28252(Windows CLFS OOB R/W➡️EoP, 0-day, may have been actively exploited/ITW)
An OOB read and write vulnerability exists in CClfsBaseFilePersisted::ExtendMetadataBlock and CClfsBaseFilePersisted::WriteMetadataBlock when parsing a malformed BLF file. The OOB read leads to one byte increment of the rgContainers[0] value, that results pointing to a fake CONTAINER_CONTEXT with a user space address 0x5000000 treated as an object's vftable pointer, detonating the placed gadgets and escalating privilege to SYSTEM.

🦠Exploit sample

⚠️The gadgets are same as the ITW exploit of CVE-2023-23376, the code layout has overlaps with the ITW exploit of CVE-2022-37969.
⚠️Exploiting the vulnerability will give a local unprivileged attacker
SYSTEM level privileges.
⚠️Any authenticated local user can exploit the vulnerability and an exploit is trivial to produce.
  • 🔥 13
  • 👍 5
  • 😍 4
More from @resoluteattack
  1. Jun 25, 2024document post
  2. Jun 9, 2024document post
  3. Jun 9, 2024FBI открыло охоту на продавцов баз данных Недавно появившаяся в открытом доступе стенограм…
  4. Jun 9, 2024⚡️⚡️⚡️⚡️⚡️⚡️⚡️⚡️ ⚡️SOON 👨‍💻
  5. Apr 17, 2024video post
  6. Dec 25, 2023document post
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →