Window Secondary Login Failed Sanitization
Posted by deepcore on March 18, 2016 – 6:27 am
The SecLogon service does not sanitize standard handles when creating a new process leading to duplicating a system service thread pool handle into a user accessible process. This can be used to elevate privileges to Local System.
Post a reply
You must be logged in to post a comment.