Microsoft Windows GDI Kernel Local Privilege Escalation Vulnerability

UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.

An exploit is available to members of the Immunity Partner's program:

https://www.immunityinc.com/downloads/immpartners/GDIWrite4.tgz

This module reportedly reliably exploits this vulnerability on Windows 2000 up to SP4 and Windows XP up to SP2.

The following proof-of-concept examples and exploits are available:


 

Privacy Statement
Copyright 2010, SecurityFocus