CVE-2023-36802 的 PoC,针对 Microsoft Kernel Streaming Service Proxy,该组件存在类型混淆漏洞。
该概念验证基于 Benoît Sevens (@benoitsevens) 的文章。文章地址:https://googleprojectzero.github.io/0days-in-the-wild//0day-RCAs/2023/CVE-2023-36802.html
原始漏洞利用及分析由 Valentina Palmiotti (@chompie1337) 完成。 https://securityintelligence.com/x-force/critically-close-to-zero-day-exploiting-microsoft-kernel-streaming-service/
注意:仅在 Windows 11 22H2 22621.1848 上测试。PreviousMode 攻击可能在内部预览版中已被缓解。
