Exploitation Summary
EIP tracks 2 public exploits for CVE-2021-26871. PoCs published by fr4nkxixi.
AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2021-26871, which involves a 'PROPVARIANT' type confusion vulnerability in the WalletService component. The PoC demonstrates a crash in the `HandleBarcodePropertyValue` function, likely leading to a denial-of-service (DoS) or potential remote code execution (RCE) condition.
Description
Windows WalletService Elevation of Privilege Vulnerability
Exploits (2)
This repository contains a proof-of-concept exploit for CVE-2021-26871, which involves a 'PROPVARIANT' type confusion vulnerability in the WalletService component. The PoC demonstrates a crash in the `HandleBarcodePropertyValue` function, likely leading to a denial-of-service (DoS) or potential remote code execution (RCE) condition.
The repository contains a functional proof-of-concept exploit for CVE-2021-26871, demonstrating a 'PROPVARIANT' type confusion vulnerability in the Windows WalletService. The provided C code triggers an access violation in the 'HandleBarcodePropertyValue' function, showcasing the vulnerability's exploitability.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H