DOCUMENTS Windows Local Privilege Escalation CVE-2024-30088
by n3od4y - 07-08-24, 10:56 AM
#21
thxxx
Reply
#22
Ty sm
Reply
#23
ขอบคุณครับ
Reply
#24
(07-08-24, 10:56 AM)n3od4y Wrote: When performing copy the SecurityAttributesList, the kernel setup the list of SecurityAttribute's structure *directly* to the user supplied pointer. After that, it calls to RtlCopyUnicodeString and AuthzBasepCopyoutInternalSecurityAttributeValues functions to copy out name and value of the SecurityAttribute structure, leading to multiple TOCTOU in this function

tty
Reply
#25
(07-08-24, 10:56 AM)n3od4y Wrote: When performing copy the SecurityAttributesList, the kernel setup the list of SecurityAttribute's structure *directly* to the user supplied pointer. After that, it calls to RtlCopyUnicodeString and AuthzBasepCopyoutInternalSecurityAttributeValues functions to copy out name and value of the SecurityAttribute structure, leading to multiple TOCTOU in this function
Reply


Forum Jump:


 Users browsing this thread: 5 Guest(s)