When performing copy the SecurityAttributesList, the kernel setup the list of SecurityAttribute's structure *directly* to the user supplied pointer. After that, it calls to RtlCopyUnicodeString and AuthzBasepCopyoutInternalSecurityAttributeValues functions to copy out name and value of the SecurityAttribute structure, leading to multiple TOCTOU in this function
DOCUMENTS Windows Local Privilege Escalation CVE-2024-30088
by n3od4y - 07-08-24, 10:56 AM
« Next Oldest | Next Newest »
|
Users browsing this thread: 1 Guest(s)