⚡️RESOLUTE ATTACK - Компания по информационной безопасности
YouTube - https://www.youtube.com/@RESOLUTE-ATTACK
Chat - @RESOLUTECHAT
Web Site - www.resolute-attack.com
Обратная связь - @ResoluteAttack_Bot
Post #798
5.22K
RE @resoluteattack
Showing posts older than #801 · Back to latest
Forwarded from Ralf Hacker Channel (Ralf Hacker)


Forwarded from Caster



Forwarded from linkmeup
Forwarded from Private Shizo
Exploiting Errors in Windows Error Reporting in 2022.pdf2.6 MBForwarded from Private Shizo


CClfsBaseFilePersisted::ExtendMetadataBlock and CClfsBaseFilePersisted::WriteMetadataBlock when parsing a malformed BLF file. The OOB read leads to one byte increment of the rgContainers[0] value, that results pointing to a fake CONTAINER_CONTEXT with a user space address 0x5000000 treated as an object's vftable pointer, detonating the placed gadgets and escalating privilege to SYSTEM.SYSTEM level privileges.