vendor:
Windows 10 Pro x64 (Pre-Anniversary)
by:
Core Security
7,2
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Windows 10 Pro x64 (Pre-Anniversary)
Affected Version From: Windows 10 Pro x64 (Pre-Anniversary)
Affected Version To: Windows 10 Pro x64 (Pre-Anniversary)
Patch Exists: Yes
Related CWE: N/A
CPE: o:microsoft:windows_10:10.0.10240.16384
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2016
Windows SMEP Bypass U=S
This exploit is a privilege escalation vulnerability in Windows 10 Pro x64 (Pre-Anniversary) and hal.dll: 10.0.10240.16384, FortiShield.sys: 5.2.3.633. It is based on the fact that the Supervisor Mode Execution Prevention (SMEP) can be bypassed by writing a specific value to a page table entry (PTE). The exploit creates a dummy file, calls MoveFileEx() and triggers a callback. Then, it writes a specific value to a page table entry (PTE) and restores the original value after the callback is triggered.
Mitigation:
The best way to mitigate this vulnerability is to update the system to the latest version of Windows 10.