Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
1874 DOCUMENTS Windows Local Privilege Escalation CVE-2024-30088
STAFF TEAM
#1
When performing copy the SecurityAttributesList, the kernel setup the list of SecurityAttribute's structure *directly* to the user supplied pointer. After that, it calls to RtlCopyUnicodeString and AuthzBasepCopyoutInternalSecurityAttributeValues functions to copy out name and value of the SecurityAttribute structure, leading to multiple TOCTOU in this function

   

Hidden Content
You must register or login to view this content.
[-] The following 1 user Likes n3od4y's post:
  • Johm
STAFF TEAM
#2
awoseom
Reply
STAFF TEAM
#3
thanks
Reply

Reply to this thread