Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-0882. PoCs published by Google Security Research.
AI-analyzed exploit summary The exploit leverages a vulnerability in Windows Desktop Bridge's virtual registry handling, where the NtLoadKey callback fails to check the Application Key flag, allowing arbitrary file creation with kernel privileges. This leads to an elevation of privilege (EoP) by dropping files in restricted directories.
Description
The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how the virtual registry is managed, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0880.
Exploits (1)
The exploit leverages a vulnerability in Windows Desktop Bridge's virtual registry handling, where the NtLoadKey callback fails to check the Application Key flag, allowing arbitrary file creation with kernel privileges. This leads to an elevation of privilege (EoP) by dropping files in restricted directories.
References (4)
Scores
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H