itm4n / PPLmedic

Dump the memory of any PPL with a Userland exploit chain

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Failed to determine the address of LdrpKnownDllDirectoryHandle on Windows 10 19045.3208

s-malik03 opened this issue · comments

I was using this PoC as part of my own exploit when I noticed that this error came on my Windows environment. I had tested it previously and it worked correctly. However, this time it repeatedly showed the error even after rebooting and resetting the system. Turns out my system had received an update on July 11. Rolling back to my previous build 19045.2965, everything works correctly. It is possible Windows has patched it. Here are the results of testing this PoC on both systems:

image
image

Microsoft just deployed a mitigation to break exploits like this.