CVE-2018-8550
HIGHWindows COM Aggregate Marshaler - Privilege Escalation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-8550. PoCs published by Google Security Research.
AI-analyzed exploit summary This is a detailed technical analysis of CVE-2018-8550, focusing on the unsafe unmarshaling in the DfMarshal COM object, which can lead to privilege escalation. The writeup explains the structure of the marshaled data, the unmarshaling process, and potential attack vectors, including bypassing session checks and leveraging the Audio Service.
Description
An elevation of privilege exists in Windows COM Aggregate Marshaler, aka "Windows COM Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Exploits (1)
This is a detailed technical analysis of CVE-2018-8550, focusing on the unsafe unmarshaling in the DfMarshal COM object, which can lead to privilege escalation. The writeup explains the structure of the marshaled data, the unmarshaling process, and potential attack vectors, including bypassing session checks and leveraging the Audio Service.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H