vendor:
Windows
by:
Nick Peterson, Nemanja Mulasmajic, Can Bölük, bwatters-r7
7.8
CVSS
HIGH
Privilege Elevation
264
CWE
Product Name: Windows
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2018-8897
CPE: N/A
Metasploit:
https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2018-10872/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2018-10872/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2018-10872/, https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-2-cve-2018-8897/, https://www.rapid7.com/db/vulnerabilities/msft-cve-2018-8897/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2018-8897/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp1-cve-2018-8897/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp2-cve-2018-8897/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2018-8897/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2018-8897/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2018-8897/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp3-cve-2018-8897/, https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2018-8897/, https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2018-8897/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2018-8897/, https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2018-8897/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2018-8897/, https://www.rapid7.com/db/vulnerabilities/apple-osx-kernel-cve-2018-8897/
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=110323, https://www.infosecmatter.com/nessus-plugin-library/?id=109667, https://www.infosecmatter.com/nessus-plugin-library/?id=110245, https://www.infosecmatter.com/nessus-plugin-library/?id=109639, https://www.infosecmatter.com/nessus-plugin-library/?id=110113, https://www.infosecmatter.com/nessus-plugin-library/?id=109619, https://www.infosecmatter.com/nessus-plugin-library/?id=110353, https://www.infosecmatter.com/nessus-plugin-library/?id=109655, https://www.infosecmatter.com/nessus-plugin-library/?id=110375, https://www.infosecmatter.com/nessus-plugin-library/?id=109727
Platforms Tested: Windows x64
2018
Microsoft Windows POP/MOV SS Local Privilege Elevation Vulnerability
This module exploits a vulnerability in a statement in the system programming guide of the Intel 64 and IA-32 architectures software developer's manual being mishandled in various operating system kerneles, resulting in unexpected behavior for #DB excpetions that are deferred by MOV SS or POP SS. This module will upload the pre-compiled exploit and use it to execute the final payload in order to gain remote code execution.
Mitigation:
Update the system with the latest security patches