header-logo
Suggest Exploit
vendor:
N/A
by:
N/A
7.8
CVSS
HIGH
POP SS vulnerability
119
CWE
Product Name: N/A
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2018-8897
CPE: N/A
Other Scripts: N/A
Platforms Tested: VMWare
2018

Demo exploitation of the POP SS vulnerability

This exploit leads to unsigned code execution with kernel privilages. KVA Shadowing should be disabled and the relevant security update should be uninstalled. This may not work with certain hypervisors (like VMWare), which discard the pending #DB after INT3.

Mitigation:

Disable KVA Shadowing and uninstall the relevant security update
Source

Exploit-DB raw data:

Demo exploitation of the POP SS vulnerability (CVE-2018-8897), leading to unsigned code execution with kernel privilages.

- KVA Shadowing should be disabled and the relevant security update should be uninstalled.
- This may not work with certain hypervisors (like VMWare), which discard the pending #DB after INT3.

Proof of Concept:
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/44697.zip