CVE-2020-1015
HIGHWindows - Elevation of Privilege via User-Mode Power Service Memory Handling
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-1015. PoCs published by 0xeb-bp.
AI-analyzed exploit summary This PoC exploits CVE-2020-1015, a local privilege escalation vulnerability in Windows via the UmpoRpcLegacyEventRegisterNotification RPC function. It triggers a race condition by rapidly registering and unregistering a service with a long name, leading to a crash or potential privilege escalation.
Description
An elevation of privilege vulnerability exists in the way that the User-Mode Power Service (UMPS) handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0934, CVE-2020-0983, CVE-2020-1009, CVE-2020-1011.
Exploits (1)
This PoC exploits CVE-2020-1015, a local privilege escalation vulnerability in Windows via the UmpoRpcLegacyEventRegisterNotification RPC function. It triggers a race condition by rapidly registering and unregistering a service with a long name, leading to a crash or potential privilege escalation.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H