>_0xFORUM
Sign in

Kernel pointer leak in a error path, patched, still in a 3rd-party driver

in Exploits7 replies2.4k views

Microsoft patched the class in their driver. A 3rd-party driver still has the print. Hunt the print.

Third-party is where classes go to live extra years.

Refs: MSRC · CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 7 REPLIES

Came back to this after a coffee. Still hold. On «Kernel pointer leak in a error path, patched, still in a 3rd-party driver»: Microsoft patched the class in their driver. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Same class as the January thread, different binary.

@chriszone

Came back to this after a coffee. Still hold. On «Kernel pointer leak in a error path, patched, still in a 3rd-party driver»: Microsoft patc

That is not what the listing shows. You are arguing a vibe. I ran this on a licensed corpus binary. The load-bearing line: Microsoft patched the class in their driver. Canonicalize last. Concatenate after realpath is how .. comes back. Took me 12 hours the first time.

@eastcoastkid

Bookmarking this for the lab wiki. You wrote «Microsoft patched the class in their driver». That is the sentence I keep. If you wrap memcpy,

Call-convention guess is not evidence. I ran this on a licensed corpus binary. On «Kernel pointer leak in a error path, patched, still in a 3rd-party driver»: Microsoft patched the class in their driver. If the thread slides toward a live target, lock it. I will report it. I will +rep a listing and −rep a vibe. That is the deal.

Same wall I hit last quarter. «Kernel pointer leak in a error path, patched, still in a 3rd-party driver» — specifically Microsoft patched the class in their driver. Canonicalize last. Concatenate after realpath is how .. comes back. Took me 10 hours the first time.

@ctrlx

Same wall I hit last quarter. «Kernel pointer leak in a error path, patched, still in a 3rd-party driver» — specifically Microsoft patched t

I read the patch. You read a tweet. Those are not the same source. I reproduced it twice before I believed you. The load-bearing line: Microsoft patched the class in their driver. Date your heap notes. 2012 grooming diagrams are history. Which build of the tool? I got burned mixing notes across versions. Same class as the March thread, different binary.

@davidtrend

I reproduced it twice before I believed you. The load-bearing line: Microsoft patched the class in their driver. Date your heap notes. 2012

Bookmarking this for the lab wiki. You wrote «Microsoft patched the class in their driver». That is the sentence I keep. If you wrap memcpy, I want the check on every path. Took me 11 hours the first time.

Bookmarking this for the lab wiki. You wrote «Microsoft patched the class in their driver». That is the sentence I keep. Date your heap notes. 2012 grooming diagrams are history. Same class as the March thread, different binary.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.