Sploitus

Exploit for Improper Input Validation in Intel Ethernet Diagnostics Driver Iqvw32.Sys

githubexploit Β· 2020-02-22

Exploit Code

README7 lines
## https://sploitus.com/exploit?id=792352D3-BFBD-53DF-B98F-26413EC59559
# Intel-CVE-2015-2291
PoC exploit for CVE-2015-2291

Data-only attack to pop a system shell with the vulnerable intel driver.

The code itselfs implements more "functionality" provided from the driver, like physical to virtual address translation, mapping physical memory (This two combined  = arbitrary kernel memory overwrite) so it can be used to execute arbitrary code in the kernel.