CVE-2015-2512
Microsoft Windows - Local Privilege Escalation via Adobe Type Manager Library
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2015-2512. PoCs published by Nils Sommer.
AI-analyzed exploit summary This exploit triggers a buffer overflow in the NtGdiBitBlt system call, specifically targeting Win 7 32-bit systems with Special Pool enabled on win32k.sys. The PoC is designed to demonstrate a reliable buffer overflow vulnerability.
Description
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Font Driver Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2507.
Exploits (2)
This exploit triggers a buffer overflow in the NtGdiBitBlt system call, specifically targeting Win 7 32-bit systems with Special Pool enabled on win32k.sys. The PoC is designed to demonstrate a reliable buffer overflow vulnerability.
The PoC demonstrates multiple pool buffer overflows in the Windows GDI component via the NtGdiStretchBlt system call, enabling write and read overflows for potential memory leaks or exploitation.