Windows DeviceApi CMApi Privilege Escalation
Posted by deepcore on October 19, 2016 – 9:48 pm
The Windows DeviceApi CMApi PnpCtxRegOpenCurrentUserKey function doesn’t check the impersonation level of the current effective token allowing a normal user to create arbitrary registry keys in another user’s loaded hive leading to elevation of privilege.
Post a reply
You must be logged in to post a comment.