Markakd / CVE-2022-2588

exploit for CVE-2022-2588
464 stars 71 forks source link

Request for the attack against cred #9

Open brant-ruan opened 1 year ago

brant-ruan commented 1 year ago

Hello, are you going to release the attack against cred?

Actually I wonder how you can leverage the high privilege cred object after freeing the victim object, as different victim objects may be in different slab caches. How can you escalate the privilege of current process by heap spraying to occupy the cred pointer within the victim object? One assumption is to do cross-cache attack. Not sure...

Thanks!