Windows NtLoadKeyEx Read Only Hive Arbitrary File Write Privilege Escalation
Posted by deepcore on October 20, 2016 – 9:58 pm
NtLoadKeyEx takes a flag to open a registry hive read only, if one of the hive files cannot be opened for read access it will revert to write mode and also impersonate the calling process. This can leading to elevation of privilege if a user controlled hive is opened in a system service.
Post a reply
You must be logged in to post a comment.