CVE-2019-0805
HIGHWindows - Elevation of Privilege via LUAFV Driver Calls
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-0805. PoCs published by Google Security Research.
AI-analyzed exploit summary The exploit demonstrates a cache poisoning vulnerability in the LUAFV driver on Windows 10 1809, allowing a user to replace the cached contents of a privileged file (e.g., license.rtf) with arbitrary data, leading to local privilege escalation. The PoC leverages delayed virtualization and section object manipulation to achieve this effect.
Description
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0836, CVE-2019-0841.
Exploits (1)
The exploit demonstrates a cache poisoning vulnerability in the LUAFV driver on Windows 10 1809, allowing a user to replace the cached contents of a privileged file (e.g., license.rtf) with arbitrary data, leading to local privilege escalation. The PoC leverages delayed virtualization and section object manipulation to achieve this effect.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H