CVE-2015-2433
Microsoft Windows - Kernel ASLR Bypass via Crafted Application
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2015-2433.
PoCs published by Metasploit, Eugene Ching, Mateusz Jurczyk, Cedric Halbronn, juan vazquez, including Metasploit module exploits/windows/local/ms15_078_atmfd_bof.
AI-analyzed exploit summary This Metasploit module exploits a pool-based buffer overflow in the Windows font driver (atmfd.dll) via a malformed font, achieving local privilege escalation on vulnerable Windows 8.1 x64 systems. It leverages reflective DLL injection and targets specific win32k.sys versions.
Description
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Kernel ASLR Bypass Vulnerability."
Exploits (2)
This Metasploit module exploits a pool-based buffer overflow in the Windows font driver (atmfd.dll) via a malformed font, achieving local privilege escalation on vulnerable Windows 8.1 x64 systems. It leverages reflective DLL injection and targets specific win32k.sys versions.
This Metasploit module exploits a pool-based buffer overflow in the atmfd.dll driver (CVE-2015-2433) by parsing a malformed font, achieving local privilege escalation on vulnerable Windows 8.1 x64 systems. It includes reflective DLL injection and targets specific win32k.sys versions for reliable exploitation.