Forget vulnerable drivers - Admin is all you need
ID: 0137ddc0-5b6e-58cd-9954-2fe37c317edc
STIX ID: report--0137ddc0-5b6e-58cd-9954-2fe37c317edc
Feed Name: Elastic Security Labs
This research write-up describes admin-to-PPL and admin-to-kernel Windows vulnerabilities and the author's disclosure to MSRC (which declined to patch), then documents the public release of exploit tools (PPLFault, GodFault) and a driverless adaptation of EDRSandBlast that can disable endpoint defenses; it includes a mitigation (NoFault), warns that vulnerable-driver and kernel exploit chains are already used by criminals, and calls for Microsoft to treat such vulnerabilities with higher urgency.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
