3 ms·
It's a code injection method. And it's an interesting approach, but dll injection with some tricks can be just as undetectable. Short version: An attacker alre
by XaYdEk 10y ago
It's a code injection method. And it's an interesting approach, but dll injection with some tricks can be just as undetectable.
Short version: An attacker already has unprivileged access to your machine (running something with your user's privilege level). The attacker can use this type of method to access other processes in the same security context (running under the same user).
Or in different terms: it's not privilege escalation, it's not remote code injection (because you already need to be in), it's a method for increasing horizontal access.
So no, the sky is not falling or not more than usual. :)