Exploiting Windows KTM Race Condition (Part 35)
ID: ff026d2f-0983-5fa1-b47f-2eb384afe15d
STIX ID: report--ff026d2f-0983-5fa1-b47f-2eb384afe15d
Feed Name: NCC Research
This part of a multi-part blog details exploiting CVE-2018-8611 in Windows KTM: how to win the use-after-free race without a debugger by suspending the recovery thread (using SuspendThread + NtQueryInformationThread), how to identify which KENLISTMENT to free (notification counting), non-paged pool feng shui using named pipes to replace freed KENLISTMENTs with controlled DATA_ENTRY chunks, and how to build "trap" and primitive userland-backed enlistments for detection, debugging and turning the UAF into higher-level read/write primitives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
