In this post, @PvdH takes a look back at an arbitrary file write vuln (CVE-2020-16885), originally discovered by @jonasLyk, expanding on the impact by showing how it could have been abused for a local privilege escalation using a DLL-side loading attack. https://sensepost.com/blog/2020/let-me-store-that-for-you/ …
Replying to @sensepost @PvdH
Yarh- there is a reason I use phoneinfo.dll in the picture, it autoexecutes as system if you run the upload error reports tasks
0 replies
1 retweet
5 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.