3 ms·
This is a company so shitty that their website does not even have a privacy policy: https://www.malwarefox.com/privacy-policy/ https://www.malwarefox.com/privac
by fazfq 4y ago
This is a company so shitty that their website does not even have a privacy policy: https://www.malwarefox.com/privacy-policy/ https://www.malwarefox.com/privacy-policy/
The exploit suddenly looks much less impressive if it relies on the user having installed something like that.
- 36933 4y agoDoes it have to be installed though? Can’t you just load the driver, if it’s signed and not on the driver block list now on 22H2?
- fazfq 4y agoYou have to be a local administrator to load a driver.
- wongarsu 4y agoEven a "local admin to Ring0 without reboot"-exploit might have some uses in malware.
- fazfq 4y agoBut that already exists. There are thousands of signed drivers; many around are bound to be exploitable. But it's not Windows' fault that you installed one. The truth of the matter is that if you are local admin you can already ruin the system in many ways. Once you are admin the game is already over.
- cestith 4y agoThe driver was chosen because there was an existing, easy-to-follow PoC exploit for the vulnerability, though. There are bound to be other drivers that are vulnerable and the VBA would change only where the vulnerability in the driver differed. Being able to do this from a document file is still plenty concerning.