Microsoft Windows SetImeInfoEx Win32k NULL Pointer Dereference
Posted by deepcore on October 20, 2018 – 4:15 pm
This Metasploit module exploits an elevation of privilege vulnerability that exists in Windows 7 and 2008 R2 when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploits this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This Metasploit module is tested against windows 7 x86, windows 7 x64 and windows server 2008 R2 standard x64.
Post a reply
You must be logged in to post a comment.