Lucene search

K
zdiWhoamiZDI-20-1365
HistoryNov 11, 2020 - 12:00 a.m.

Microsoft Windows bindflt Driver Missing Authentication Privilege Escalation Vulnerability

2020-11-1100:00:00
whoami
www.zerodayinitiative.com
30
microsoft windows
bindflt driver
privilege escalation
vulnerability
low-privileged code
ioctl
remapping of directories
system.

EPSS

0

Percentile

9.7%

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the bindflt.sys driver. A crafted request with an IOCTL of 0x220000 can perform remapping of directories. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM.