You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Was hoping to get BdApiUtil.sys added to this as a vulnerable driver. I wasn't sure the best place to do that, so opened an issue.
Summary:
I found an IOCTL code which takes a PID and terminates it (arbitrary process termination). Admin privileges required to install the driver, but if it's already installed, can be called by any user (non admin).
Here's the specific version I tested against in VT (likely other versions vulnerable too):
Was hoping to get BdApiUtil.sys added to this as a vulnerable driver. I wasn't sure the best place to do that, so opened an issue.
Summary:
I found an IOCTL code which takes a PID and terminates it (arbitrary process termination). Admin privileges required to install the driver, but if it's already installed, can be called by any user (non admin).
Here's the specific version I tested against in VT (likely other versions vulnerable too):
https://www.virustotal.com/gui/file/06e06ae13911ada97cc955379a0697a7698192699dcfde5c197318fa024911b1
IOCTL needed is 0x800024B4
PoC:
The text was updated successfully, but these errors were encountered: