Microsoft Windows Kernel ATMFD.DLL NamedEscape 0x250D Pool Corruption

Discussion in 'News Aggregator' started by Packet Storm, 10 Jan 2018.

  1. Packet Storm

    Packet Storm Guest

    The Microsoft Windows OpenType ATMFD.DLL kernel-mode font driver has an undocumented "escape" interface, handled by the standard DrvEscape and DrvFontManagement functions implemented by the module. The interface is very similar to Buffered IOCTL in nature, and handles 13 different operation codes in the numerical range of 0x2502 to 0x2514. It is accessible to user-mode applications through an exported (but not documented) gdi32!NamedEscape function, which internally invokes the NtGdiExtEscape syscall.

    Continue reading...
     

Share This Page

Loading...