m417z / blog · Jan 11, 2024
Privilege escalation using the XAML diagnostics API (CVE-2023-36003)
0Sign in to vote or save
This page did not load. You can still read it on the original site — the toolbar below keeps your place in the directory.
This is a write-up of a vulnerability that I discovered in Windows. The vulnerability was patched in December’s Patch Tuesday, and the CVE assigned to it is CVE-2023-36003. The vulnerability allows a non-elevated process to inject a DLL into an elevated or otherwise inaccessible process, allowing for privilege escalation. The vulnerability is caused by a lack of security checks in the…
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.