Microsoft Windows SMB Server Mount Point Privilege Escalation
Posted by deepcore on January 12, 2018 – 7:17 am
On Microsoft Windows, the SMB server drivers (srv.sys and srv2.sys) do not check the destination of a NTFS mount point when manually handling a reparse operation leading to being able to locally open an arbitrary device via an SMB client which can result in privilege escalation.
Post a reply
You must be logged in to post a comment.