Windows AppLocker 驱动程序本地提权漏洞——CVE-2024-21338
crowdfense.com | 漏洞 | CVE-2024-21338 | #lpe | #poc | #windows-kernel | #cve-2024-21338 | #applocker | #appid-sys | #smep | #kcfg
摘要
深入分析 CVE-2024-21338:Windows AppLocker 驱动 appid.sys 的不可信指针解引用漏洞,可导致内核权限提升。文章覆盖根因、SMEP/kCFG 绕过、KASLR 处理与两版 POC,该漏洞因 Lazarus FudModule Rootkit 而广为人知。
- 发布时间
- 收录时间
Skip to content