The Agere Windows Modem module (ltmdm64.sys) present in Microsoft Windows is vulnerable to an untrusted pointer dereference, which can result in arbitrary memory write. This module allows a local unprivileged user to execute arbitrary code with SYSTEM privileges. The steps performed by the exploit are: Leak the address of the current process Leak the address of the System process Leak the address of the I/O ring Trigger the vulnerability to overwrite IoRing->RegBuffersCount Trigger the vulnerability to overwrite IoRing->RegBuffers Leak the address of the System process token using I/O ring Overwrite the current process token using I/O ring Reset IoRing->RegBuffersCount to 0 Inject the agent into an elevated process
CVE Link
Exploit Platform
Exploit Type
Product Name