EIP-2026-117549
PRE-CVEMicrosoft Windows 10 - 'pcap' Driver Privilege Escalation
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-117549. PoCs published by Rootkitsmm.
AI-analyzed exploit summary This exploit targets a Windows kernel vulnerability by leveraging a vulnerable driver (WTCAP_A) to overwrite a token object address, enabling local privilege escalation. It uses undocumented NtQuerySystemInformation to locate token handles and crafts an IOCTL request to manipulate kernel memory.
Description
Microsoft Windows 10 - 'pcap' Driver Privilege Escalation
Exploits (1)
This exploit targets a Windows kernel vulnerability by leveraging a vulnerable driver (WTCAP_A) to overwrite a token object address, enabling local privilege escalation. It uses undocumented NtQuerySystemInformation to locate token handles and crafts an IOCTL request to manipulate kernel memory.