CVE-2019-1089
HIGHWindows RPCSS - Authenticated Privilege Escalation via Improper RPC Request Handling
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-1089. PoCs published by Google Security Research.
AI-analyzed exploit summary The exploit leverages a flaw in the RPCSS Activation Kernel RPC server's security callback caching mechanism, allowing a low-privileged user to bypass PID checks and access privileged operations, such as setting arbitrary SYSAPPID values for sandbox escape.
Description
An elevation of privilege vulnerability exists in rpcss.dll when the RPC service Activation Kernel improperly handles an RPC request. To exploit this vulnerability, a low level authenticated attacker could run a specially crafted application. The security update addresses this vulnerability by correcting how rpcss.dll handles these requests., aka 'Windows RPCSS Elevation of Privilege Vulnerability'.
Exploits (1)
The exploit leverages a flaw in the RPCSS Activation Kernel RPC server's security callback caching mechanism, allowing a low-privileged user to bypass PID checks and access privileged operations, such as setting arbitrary SYSAPPID values for sandbox escape.
References (2)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H