CVE-2015-1515
SoftSphere DefenseWall Personal Firewall 3.24 - Privilege Escalation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-1515. PoCs published by Parvez Anwar.
AI-analyzed exploit summary This exploit targets a privilege escalation vulnerability in SoftSphere DefenseWall FW/IPS (CVE-2015-1515) by leveraging arbitrary write to overwrite the HalDispatchTable in the kernel, achieving token stealing for SYSTEM privileges. It includes shellcode for token manipulation and spawns a command shell upon successful exploitation.
Description
The dwall.sys driver in SoftSphere DefenseWall Personal Firewall 3.24 allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted 0x00222000, 0x00222004, 0x00222008, 0x0022200c, or 0x00222010 IOCTL call.
Exploits (1)
This exploit targets a privilege escalation vulnerability in SoftSphere DefenseWall FW/IPS (CVE-2015-1515) by leveraging arbitrary write to overwrite the HalDispatchTable in the kernel, achieving token stealing for SYSTEM privileges. It includes shellcode for token manipulation and spawns a command shell upon successful exploitation.