Skip to content

Wh04m1001/UserManagerEoP

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 

Repository files navigation

UserManagerEoP

This is exploit for CVE-2023-36047 i found last year.

The flaw was in usermanager service which copied files from user controllable directory which results in EoP. After first fix MSRC only fixed write part of copy operation while read operation was still performed in NT AUTHORITY\SYSTEM context. This can be abused to SAM/SYSTEM/SECURITY hives from shadow copy, today MSRC fixed this vulnerability and is tracked as CVE-2024-21447

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published