mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-31 18:29:31 +02:00
51 lines
4.8 KiB
Markdown
51 lines
4.8 KiB
Markdown
### [CVE-2020-1377](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1377)
|
|

|
|

|
|

|
|

|
|

|
|

|
|

|
|

|
|

|
|

|
|

|
|

|
|

|
|

|
|

|
|
&color=blue)
|
|

|
|
&color=blue)
|
|

|
|
&color=blue)
|
|
&color=blue)
|
|

|
|

|
|
&color=blue)
|
|

|
|
&color=blue)
|
|

|
|

|
|
&color=blue)
|
|
&color=blue)
|
|

|
|

|
|

|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system.A locally authenticated attacker could exploit this vulnerability by running a specially crafted application.The security update addresses the vulnerability by helping to ensure that the Windows Kernel API properly handles objects in memory.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- http://packetstormsecurity.com/files/158938/Microsoft-Windows-CmpDoReDoCreateKey-Arbitrary-Registry-Key-Creation-Privilege-Escalation.html
|
|
|
|
#### Github
|
|
- https://github.com/punishell/WindowsLegacyCVE
|
|
|