
Exploits CVE-2019-16098 in the RTCore64.sys driver to escalate from a low-privileged account to SYSTEM by copying the System process token.
This CVE exploits the RTCore64.sys driver and creates a cmd.exe process with system privileges by copying the token of the System process with one of the low-privilege cmd.exe process.
Blog about the approach and the methodology can be found here.