Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-31771. PoCs published by restdone.
AI-analyzed exploit summary This repository provides a detailed technical writeup for CVE-2024-31771, an arbitrary file write vulnerability in TotalAV 6.0.x. It describes the exploitation steps involving DLL quarantine, junction creation, and privilege escalation via Windows Update service.
Description
Insecure Permission vulnerability in TotalAV v.6.0.740 allows a local attacker to escalate privileges via a crafted file
Exploits (1)
This repository provides a detailed technical writeup for CVE-2024-31771, an arbitrary file write vulnerability in TotalAV 6.0.x. It describes the exploitation steps involving DLL quarantine, junction creation, and privilege escalation via Windows Update service.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H