Microsoft Windows Code injection...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Overview We’d like to introduce a new Zero-Day technique for injecting code and maintaining persistency on a machine (i.e. auto-run) dubbed DoubleAgent. DoubleAgent can exploit: Every Windows version (Windows XP to Windows 10) Every Windows architecture (x86 and x64) Every Windows user (SYSTEM/Adminetc.)Every target process, including privileged processes (OS/Antivirus/etc.) DoubleAgent exploits a 15 years old undocumented legitimate feature of Windows and therefore cannot be patched. #### Code Injection DoubleAgent gives the attacker the ability to inject any DLL into any process. The code injection occurs extremely early during the victim’s process boot, giving the attacker full control over the process and no way for the process to protect itself. The code injection technique is so revolutionary that it’s not detected or blocked by any antivirus. #### Persistency DoubleAgent can continue injecting code even after reboot making it a perfect persistency technique to “survive”...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息