Windows NtLoadKeyEx Read Only Hive Arbitrary File Write Privilege Escalation

Discussion in 'News Aggregator' started by Packet Storm, 20 Oct 2016.

  1. Packet Storm

    Packet Storm Guest

    NtLoadKeyEx takes a flag to open a registry hive read only, if one of the hive files cannot be opened for read access it will revert to write mode and also impersonate the calling process. This can leading to elevation of privilege if a user controlled hive is opened in a system service.

    Continue reading...
     

Share This Page

Loading...