Subscribe via feed.

Microsoft Windows Kernel nt!NtTraceControl Memory Disclosure

Posted by deepcore on May 17, 2017 – 11:15 am

The handler of the nt!NtTraceControl system call (specifically the EtwpSetProviderTraitsUm functionality, opcode 0x1E) discloses portions of uninitialized pool memory to user-mode clients on Microsoft Windows 10 systems.


This post is under “exploit” and has no respond so far.
If you enjoy this article, make sure you subscribe to my RSS Feed.

Post a reply

You must be logged in to post a comment.