Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-5717. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit leverages a type confusion vulnerability in the Intel Content Protection HECI Service, allowing an attacker to elevate privileges to SYSTEM by manipulating a DCOM object. The PoC demonstrates arbitrary memory access via a crafted SAFEARRAY structure passed as a BSTR, leading to potential code execution.
Description
Type Confusion in Content Protection HECI Service in Intel Graphics Driver allows unprivileged user to elevate privileges via local access.
Exploits (1)
This exploit leverages a type confusion vulnerability in the Intel Content Protection HECI Service, allowing an attacker to elevate privileges to SYSTEM by manipulating a DCOM object. The PoC demonstrates arbitrary memory access via a crafted SAFEARRAY structure passed as a BSTR, leading to potential code execution.
References (2)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H