Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
How could an attacker exploit this vulnerability? An attacker who already has kernel-level access could exploit this vulnerability by submitting a specially crafted Code Integrity policy to an affected system. Successful exploitation could allow the attacker to execute code in Virtual Trust Level 1 (VTL1). What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain Virtual Trust Level 1 (VTL1) privileges.
<a href="https://x.com/vmpr0be">vmpr0be</a>