CVE-2023-52271
MEDIUM EXPLOITEDTopaz Antifraud <2.0.0.0 - Privilege Escalation
Title source: llmExploitation Summary
CVE-2023-52271 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including victoni.
AI-analyzed exploit summary This PoC exploits CVE-2023-52271 in the wsftprm.sys kernel driver (v2.0.0.0) to terminate PPL processes, primarily targeting AV/EDR processes. It uses IOCTL 0x22201C to send a PID to the driver, which then terminates the process.
Description
The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process Light) process via an IOCTL (which will be named at a later time).
Exploits (1)
This PoC exploits CVE-2023-52271 in the wsftprm.sys kernel driver (v2.0.0.0) to terminate PPL processes, primarily targeting AV/EDR processes. It uses IOCTL 0x22201C to send a PID to the driver, which then terminates the process.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H