Microsoft Windows SMB Server Mount Point Privilege Escalation

Discussion in 'News Aggregator' started by Packet Storm, 12 Jan 2018.

  1. Packet Storm

    Packet Storm Guest

    On Microsoft Windows, the SMB server drivers (srv.sys and srv2.sys) do not check the destination of a NTFS mount point when manually handling a reparse operation leading to being able to locally open an arbitrary device via an SMB client which can result in privilege escalation.

    Continue reading...
     

Share This Page

Loading...