root@deepquest.code511.com:~# 

>> Windows DeviceApi CMApi Privilege Escalation

The Windows DeviceApi CMApi PnpCtxRegOpenCurrentUserKey function doesn’t check the impersonation level of the current effective token allowing a normal user to create arbitrary registry keys in another user’s loaded hive leading to elevation of privilege.

> POST_COMMENT