vendor:
Windows 10
by:
N/A
7.2
CVSS
HIGH
Windows: NtImpersonateAnonymousToken AC to Non-AC EoP
264
CWE
Product Name: Windows 10
Affected Version From: Windows 10 1703
Affected Version To: Windows 10 1709
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2020
Windows: NtImpersonateAnonymousToken AC to Non-AC EoP
There's a missing check for impersonation level in NtImpersonateAnonymousToken when considering if the caller is currently an AC. This results in the function falling into the restricted token case if the caller is impersonating a non AC token at identification or below, leading to Elevation of Privilege.
Mitigation:
Ensure that the NtImpersonateAnonymousToken function is properly checking the impersonation level of the caller.