CVE-2019-0730
HIGHWindows - Privilege Escalation via LUAFV Driver Improper Call Handling
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-0730. PoCs published by Google Security Research.
AI-analyzed exploit summary The exploit leverages a vulnerability in the LUAFV driver where the DesiredAccess parameter, including MAXIMUM_ACCESS, is reused when virtualizing a file, leading to an Elevation of Privilege (EoP). The PoC demonstrates how a normal user can overwrite a file they shouldn't have access to by manipulating file virtualization and hardlinks.
Description
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836, CVE-2019-0841.
Exploits (1)
The exploit leverages a vulnerability in the LUAFV driver where the DesiredAccess parameter, including MAXIMUM_ACCESS, is reused when virtualizing a file, leading to an Elevation of Privilege (EoP). The PoC demonstrates how a normal user can overwrite a file they shouldn't have access to by manipulating file virtualization and hardlinks.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H