Microsoft Windows is vulnerable to a use-after-free in win32kfull!WindowActions::xxxInterceptSetWindowPos. The vulnerability can be triggered while processing deferred window-position operations for intercept windows, allowing freed kernel memory to be reclaimed with attacker-controlled allocations. This module allows a local unprivileged user to execute arbitrary code with SYSTEM privileges. The steps performed by the binary exploit are: Create intercept windows and deferred window-position objects to trigger the use-after-free Perform heap feng shui and spray restricted token objects to reclaim the freed allocation Corrupt a duplicated token's user and group information and replace it with SYSTEM security identifiers Impersonate the corrupted token and use winlogon.exe as the parent of a new elevated process Execute the uploaded agent as SYSTEM
Exploit Platform
Exploit Type
Product Name