Exploitation Summary
EIP tracks 2 public exploits for CVE-2023-36003. PoCs published by m417z, johnnygreeme.
AI-analyzed exploit summary This is a functional privilege escalation PoC for CVE-2023-36003, exploiting the XAML diagnostics API to inject a DLL into an elevated or inaccessible process. The exploit uses a COM-based TAP (Tracing and Profiling) component to execute arbitrary code (e.g., launching cmd.exe) in the context of the targeted process.
Description
XAML Diagnostics Elevation of Privilege Vulnerability
Exploits (2)
This is a functional privilege escalation PoC for CVE-2023-36003, exploiting the XAML diagnostics API to inject a DLL into an elevated or inaccessible process. The exploit uses a COM-based TAP (Tracing and Profiling) component to execute arbitrary code (e.g., launching cmd.exe) in the context of the targeted process.
The repository claims to be a PoC for CVE-2023-36003, a Windows Defender Exploit Protection bypass, but the provided C++ code only tests memory allocation behavior in std::string and local buffer overflows, which are unrelated to the described vulnerability. The code does not demonstrate the actual exploit mechanism.
References (1)
Scores
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H