A Windows Component Based Servicing elevation of privilege vulnerability allows a local attacker to make a SYSTEM TiWorker process load an unsigned sibling dpx.dll from a controlled OnePackage metadata directory. The module performs the following steps: Generates a per-run CORE Impact agent DLL named dpx.dll. Copies the target's installed, signed UpdateAgent.dll and builds a reduced DesktopDeployment cabinet with the controlled dpx.dll. Builds a small standalone OnePackage carrier on the target by using the Windows makecab utility. Executes the CBS helper directly from memory without writing the helper executable to the target filesystem. Invokes the public CBS Session COM endpoint and evaluates applicability without staging, installing, or committing the package. Causes UpdateAgent.dll to load the controlled sibling dpx.dll inside TiWorker.exe.
CVE Link
Exploit Platform
Exploit Type
Product Name