Microsoft Windows Kernel nt!NtTraceControl Memory Disclosure
Posted by deepcore on May 17, 2017 – 11:15 am
The handler of the nt!NtTraceControl system call (specifically the EtwpSetProviderTraitsUm functionality, opcode 0x1E) discloses portions of uninitialized pool memory to user-mode clients on Microsoft Windows 10 systems.
Post a reply
You must be logged in to post a comment.