Microsoft Windows NT OS Kernel Elevation of Privilege Vulnerability Exploit

The Microsoft Windows NT OS Kernel is affected by an elevation of privilege vulnerability. This module executes a BOF payload that attempts to elevate the current agent process to SYSTEM privileges. The steps performed by the exploit to elevate privileges are: Prepare WMI QuerySingleMultiple buffers and spray NPFS pipe objects in kernel pool Open a WMIDataDevice handle and resolve a WMI instance suitable for the vulnerable query path Trigger the vulnerable WMI query to corrupt an adjacent pipe object Use the corrupted pipe to leak kernel pool metadata and build an arbitrary read primitive Locate the current process and SYSTEM process objects, then read the SYSTEM token Self-elevate the current agent by writing the SYSTEM token into its own process token field
Exploit Platform
Product Name