超级巡警 <= v4 Build0316...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

该漏洞是我2010年4月6日晚上,通过自己的IoControl Fuzz工具挖掘的。漏洞存在于超级巡警ASTDriver.sys这个驱动中,影响超级巡警v4 Build0316和以前的版本。利用该漏洞能够实现本地特权提升,进Ring0。 PAGE_FAULT_IN_NONPAGED_AREA (50) Invalid system memory was referenced. This cannot be protected by try-except, it must be protected by a Probe. Typically the address is just plain bad or it is pointing at freed memory. Arguments: Arg1: 89441428, memory referenced. Arg2: 00000001, value 0 = read operation, 1 = write operation. Arg3: f9c7569b, If non-zero, the instruction address which referenced the bad memory address. Arg4: 00000000, (reserved) PROCESS_NAME: ast.exe TRAP_FRAME: f94f1b00 -- (.trap 0xfffffffff94f1b00) ErrCode = 00000002 eax=89441428 ebx=81266840 ecx=89441428 edx=ffa7c2d8 esi=81312da0 edi=811fc230 eip=f9c7569b esp=f94f1b74 ebp=f94f1b90 iopl=0 nv up ei ng nz ac pe nc cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010296 ASTDriver+0x169b: f9c7569b c70000000000 mov dword ptr [eax],0 ds:0023:89441428=???????? Resetting default scope STACK_TEXT:...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息