This module exploits a vulnerability in Microsoft MSHTML, which can be leveraged to execute arbitrary code on vulnerable machines by convincing an unsuspecting user to visit a malicious web site.
The MODAPI.sys driver in MSI Dragon Center 2.0.104.0 exposes functionality that allows low-privileged users to write an arbitrary value to a Model-Specific Register (MSR) at the specified address via specially crafted IOCTL requests.
An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
The MsIo64.sys driver before 1.1.19.1016 in MSI Dragon Center exposes functionality that allows low-privileged users to interact with the device and exploit a stack buffer overflow via specially crafted IOCTL requests and elevate system privileges.
An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
This module uses ioctls Write to IO Ports and generate a reboot
This module exploits a JSON deserialization vulnerability present in the test alert actions of SolarWinds Orion Network Performance Monitor. The deployed agent will run with the privileges of the "IIS Worker Process" process (NT AUTHORITY\NETWORK SERVICE).
The vulnerability has been dubbed PrintNightmare and is tracked as CVE-2021-34527. The flaw is due to the Windows Print Spooler service improperly performing privileged file operations. Microsoft says the flaw can be exploited by an authenticated user calling RpcAddPrinterDriverEx(). When exploited, an attacker gains SYSTEM privileges and can execute arbitrary code, install programs, view, change, or delete data or create new accounts with full user rights.
A Local Privilege Escalation vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges.
An elevation of privilege vulnerability exists in the way the Windows Graphics Component handles objects in memory.
Pagination
- Previous page
- Page 18
- Next page