Exploiting MS16-098 RGNOBJ Integer Overflow on Windows 8.1 x64 bit by abusing GDI objects
ID: 0717d5ee-4456-587e-88a9-5563ed9b95a1
STIX ID: report--0717d5ee-4456-587e-88a9-5563ed9b95a1
Feed Name: SensePost Blog
This is a step-by-step technical walkthrough of exploiting an integer overflow in win32k!bFill (MS16-098) on Windows 8.1 x64: the author reverses the patch, demonstrates how to trigger and control the overflow via GDI Path/PolylineTo calls, performs kernel pool feng shui, abuses Bitmap objects for arbitrary kernel read/write, and uses that primitive to replace the current process token with SYSTEM; exploit code and details are provided and the vulnerability is identified as patched (MS16-098).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
