EIP-2026-117479
PRE-CVEMicrosoft Data Sharing - Local Privilege Escalation (PoC)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-117479. PoCs published by SandboxEscaper.
AI-analyzed exploit summary The writeup describes an arbitrary file deletion vulnerability in the `RpcDSSMoveFromSharedFile` function exposed over ALPC, caused by a lack of impersonation due to an early revert to self. The PoC exploits this to delete `pci.sys` by retrying until timing conditions are met, requiring multi-core VMs for reliability.
Description
Microsoft Data Sharing - Local Privilege Escalation (PoC)
Exploits (1)
The writeup describes an arbitrary file deletion vulnerability in the `RpcDSSMoveFromSharedFile` function exposed over ALPC, caused by a lack of impersonation due to an early revert to self. The PoC exploits this to delete `pci.sys` by retrying until timing conditions are met, requiring multi-core VMs for reliability.