Abusing GDI Objects for ring0 Primitives Revolution
ID: 27dcc7cf-d80e-5e91-81a1-21928c95880f
STIX ID: report--27dcc7cf-d80e-5e91-81a1-21928c95880f
Feed Name: SensePost Blog
This report documents a detailed research and exploit demonstration that abuses GDI Palette objects (XEPALOBJ) and an integer overflow in Win32k!EngRealizeBrush (patched by MS17-017) to obtain arbitrary kernel memory read/write and escalate a user process to SYSTEM. The author explains the internal XEPALOBJ structure, read/write primitives via Get/Set/AnimatePalette, how to trigger the allocation overflow via patterned bitmaps, kernel pool feng-shui to position vulnerable and target objects, and the final steps to locate worker/manager palettes and replace the process token to spawn a SYSTEM shell. The write-up includes code snippets, debugging evidence, and references to the original whitepaper and tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
