Patch diff to SYSTEM
ID: 95598355-6734-5936-87ee-4a3d5c404c4d
STIX ID: report--95598355-6734-5936-87ee-4a3d5c404c4d
Feed Name: Elastic Security Labs
This write-up analyzes a Use-After-Free in CSynchronousSuperWetInk in dwmcore.dll (Windows DWM) that allows a local unprivileged process using DirectComposition to create a dangling pointer and trigger a virtual call leading to arbitrary code execution and escalation to SYSTEM; it includes the bug root cause, the Microsoft patch behavior, a full exploit which reclaims the freed allocation via a CRegionGeometry RECT spray (GetRECT), and a CFG-respecting gadget chain that makes the sprayed region executable and runs inline shellcode to spawn cmd.exe.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
