hakaioffsec / CVE-2024-21338

Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

seems to fail in impersonate local service

ricnar456 opened this issue · comments

error 0xc0000022 when tries to open the driver handle.

Is needed some special local service running in the machine? i have a lot of svchost local services running but it fails when tries ti impersonate them.

You only need to have the appid.sys service running in order for this to work. Please verify if your Windows version is older than the patch made by MSRC: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21338