Exploiting a Leaked Thread Handle
projectzero.google | blog | #privilege-escalation | #windows | #exploitation | #handle-leak | #ms16-032
Summary
A bug in the Windows Secondary Logon service, fixed as MS16-032, leaks a fully accessible thread handle from a privileged process, enabling privilege escalation without memory corruption.
- Published
- Collected
Skip to content