header-logo
Suggest Exploit
vendor:
Windows
by:
Sam B
9,3
CVSS
HIGH
Windows Kernel Exploitation
119
CWE
Product Name: Windows
Affected Version From: Windows 7
Affected Version To: Windows 8.1
Patch Exists: YES
Related CWE: CVE-2014-4113
CPE: o:microsoft:windows_8.1
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2014

Exploiting CVE-2014-4113

CVE-2014-4113 is a vulnerability in the Windows kernel that allows an attacker to gain SYSTEM privileges. The vulnerability exists in the way the Windows kernel handles objects in memory. An attacker can exploit this vulnerability by sending a specially crafted IOCTL request to a vulnerable driver. This will allow the attacker to gain SYSTEM privileges and execute arbitrary code in the kernel.

Mitigation:

Microsoft released a patch for this vulnerability in October 2014.
Source

Exploit-DB raw data:

Sources:
https://labs.mwrinfosecurity.com/assets/BlogFiles/mwri-lab-exploiting-cve-2014-4113.pdf
https://github.com/sam-b/CVE-2014-4113

EDB Mirror: https://www.exploit-db.com/docs/english/39665-windows-kernel-exploitation-101-exploiting-cve-2014-4113.pdf


Trigger and exploit code for CVE-2014-4113:

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/39666.zip