CVE-2023-38817
HIGH EXPLOITEDInspect Element Ltd Echo.ac <5.2.1.0 - Privilege Escalation
Title source: llmExploitation Summary
CVE-2023-38817 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including vxcall, SecSecBurger.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2023-38817, leveraging a vulnerable signed driver to achieve kernel-mode read/write memory operations from user-mode. The exploit uses MmCopyVirtualMemory and lacks proper access control over its IOCTLs, enabling privilege escalation.
Description
An issue in Inspect Element Ltd Echo.ac v.5.2.1.0 allows a local attacker to gain privileges via a crafted command to the echo_driver.sys component. NOTE: the vendor's position is that the reported ability for user-mode applications to execute code as NT AUTHORITY\SYSTEM was "deactivated by Microsoft itself."
Exploits (2)
This repository contains a functional exploit for CVE-2023-38817, leveraging a vulnerable signed driver to achieve kernel-mode read/write memory operations from user-mode. The exploit uses MmCopyVirtualMemory and lacks proper access control over its IOCTLs, enabling privilege escalation.
This is a functional exploit for CVE-2023-38817, demonstrating a local privilege escalation (LPE) via arbitrary kernel memory read/write operations. The code interacts with a vulnerable driver (EchoDrv) to escalate privileges by overwriting the current process's token with the system token.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H