
CVE-2023-36802 Microsoft Kernel Streaming Service Proxy の PoC
CVE-2023-36802 Microsoft Kernel Streaming Service Proxy の型混淆の脆弱性を利用した PoC です。
この Proof-of-Concept は Benoît Sevens (@benoitsevens) による write-up を基にモデル化されています。記事はこちら: https://googleprojectzero.github.io/0days-in-the-wild//0day-RCAs/2023/CVE-2023-36802.html
オリジナルのエクスプロイトと write-up は Valentina Palmiotti (@chompie1337) によるものです。 https://securityintelligence.com/x-force/critically-close-to-zero-day-exploiting-microsoft-kernel-streaming-service/
注意: この PoC は Windows 11 22H2 22621.1848 でのみテストされています。PreviousMode 攻撃は Insider ビルドでは軽減されている可能性があります。
