CVE-2019-0836
HIGHWindows - Elevation of Privilege via LUAFV Driver Race Condition
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-0836. PoCs published by Google Security Research.
AI-analyzed exploit summary The exploit leverages a race condition in the LUAFV driver's LuafvPostReadWrite callback to overwrite SECTION_OBJECT_POINTERS, allowing elevation of privilege by mapping a delay-virtualized file as read-write. The PoC demonstrates this by mapping license.rtf writable, enabling modification of the original file.
Description
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0841.
Exploits (1)
The exploit leverages a race condition in the LUAFV driver's LuafvPostReadWrite callback to overwrite SECTION_OBJECT_POINTERS, allowing elevation of privilege by mapping a delay-virtualized file as read-write. The PoC demonstrates this by mapping license.rtf writable, enabling modification of the original file.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H