Windows User Mode Font Driver Thread Permissions EoP

Discussion in 'News Aggregator' started by Packet Storm, 19 Sep 2015.

  1. Packet Storm

    Packet Storm Guest

    The host process for the UMFD runs as a normal user but with a heavily restrictive process DACL. It's possible execute arbitrary code within the context of the process because it's possible to access the processes threads leading to local EoP.

    Continue reading...
     

Share This Page

Loading...