BlueKeep RDP Remote Windows Kernel Use-After-Free
Posted by deepcore on September 24, 2019 – 5:51 am
The RDP termdd.sys driver improperly handles binds to internal-only channel MS_T120, allowing a malformed Disconnect Provider Indication message to cause a use-after-free. With a controllable data/size remote nonpaged pool spray, an indirect call gadget of the freed channel is used to achieve arbitrary code execution.
Post a reply
You must be logged in to post a comment.