Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-5189. PoCs published by Fidus InfoSecurity.
AI-analyzed exploit summary This exploit targets CVE-2018-5189, a local privilege escalation vulnerability in the WINDRVR1251 driver. It uses a race condition to achieve arbitrary kernel memory writes, ultimately executing token-stealing shellcode to elevate privileges to SYSTEM.
Description
Race condition in Jungo Windriver 12.5.1 allows local users to cause a denial of service (buffer overflow) or gain system privileges by flipping pool buffer size, aka a "double fetch" vulnerability.
Exploits (1)
This exploit targets CVE-2018-5189, a local privilege escalation vulnerability in the WINDRVR1251 driver. It uses a race condition to achieve arbitrary kernel memory writes, ultimately executing token-stealing shellcode to elevate privileges to SYSTEM.
References (2)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H