vendor:
Windows
by:
Exploit Database
7.2
CVSS
HIGH
Elevation of Privilege
269
CWE
Product Name: Windows
Affected Version From: Windows 10 1703
Affected Version To: Windows 10 1709
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 1703 and 1709
2020
Windows: NtImpersonateAnonymousToken LPAC to Non-LPAC EoP
When impersonating the anonymous token in an LPAC the WIN://NOAPPALLPKG security attribute is ignored leading to impersonating a non-LPAC token leading to EoP.
Mitigation:
Ensure that the WIN://NOAPPALLPKG attribute is forwarded on to the new token in SepGetAnonymousToken.