WeSearch

MiniPlasma

·1 min read · 0 reactions · 0 comments · 11 views
#cybersecurity#vulnerability#windows#exploit#privilege escalation#MiniPlasma#James Forshaw#Google Project Zero#Microsoft#CVE-2020-17103#Windows#cldflt!HsmOsBlockPlaceholderAccess
MiniPlasma
⚡ TL;DR · AI summary

A vulnerability in the cldflt!HsmOsBlockPlaceholderAccess routine, previously reported by James Forshaw of Google Project Zero and supposedly patched as CVE-2020-17103, remains unpatched in Windows. The original proof-of-concept exploit still works, allowing for potential privilege escalation to SYSTEM. Researcher MiniPlasma demonstrated the issue by weaponizing the PoC to spawn a SYSTEM shell, indicating a possible failure in Microsoft's patching process.

Key facts
Original article
GitHub
Read full at GitHub →
Opening excerpt (first ~120 words) tap to expand

MiniPlasma After re-investigating the technique used in GreenPlasma (specifically SetPolicyVal), it turns out cldflt!HsmOsBlockPlaceholderAccess is still vulnerable to the exact same issue that was reported to Microsoft 6 years ago. I'm not taking full credit for this, James Forshaw from google project zero found the vulnerability and reported it to Microsoft and was supposedly fixed as CVE-2020-17103. However, a research who's a friend of mine pointed out that the routine might still have a vulnerability, which is something I considered but brushed off because I thought it was impossible for Microsoft to just not patch this or rollback the patch.

Excerpt limited to ~120 words for fair-use compliance. The full article is at GitHub.

Anonymous · no account needed
Share 𝕏 Facebook Reddit LinkedIn Threads WhatsApp Bluesky Mastodon Email

Discussion

0 comments

More from GitHub