Sploitus

Exploit for Untrusted Pointer Dereference in Microsoft

githubexploit · 2023-04-20

Exploit Code

README15 lines
## https://sploitus.com/exploit?id=1CF38F98-5ABB-51BF-9844-75A5F3EB675D
# CVE-2023-21768 – AFD-for-WinSock-EoP-exploit  
Analysis article:  
https://mp.weixin.qq.com/s/9W9puJltbK-xto2A1duqgQ  
https://www.zoemurmure.top/posts/cve_2023_21768/  

According to “Patch Tuesday -> Exploit Wednesday: Pwning Windows Ancillary Function Driver for WinSock (afd.sys) in 24 Hours” (https://securityintelligence.com/posts/patch-tuesday-exploit-wednesday-pwning-windows-ancillary-function-driver-winsock/), this exploit was developed independently. Code for cleanup after privilege escalation was added, allowing successful privilege escalation. Testing platform: Windows 11 22621.963; Windows Feature Experience Pack 1000.22638.1000.0.  

Screenshot of execution:  
![screenshot-20230420-163108](https://user-images.githubusercontent.com/43516782/233308029-b26fa71a-2eee-4f8e-88d1-3d1852355d6b.png)  

Privilege escalation succeeded:  
![screenshot-20230420-163018](https://user-images.githubusercontentCom/43516782/233307633-064f6b7e-5fe3-4e86-98d6-08b65ecbc3cd.png)

[source-iocs-preserved url=https://user-images.githubusercontent.com/43516782/233307633-064f6b7e-5fe3-4e86-98d6-08b65ecbc3cd.png]