ID:6584 - Exploit for Buffer overflow in Windows and Windows Server - CVE-2020-17087
Published: July 29, 2021
Windows
Windows Server
Link to public exploit:
Vulnerability description
The vulnerability allows a local user to escalate privilege son the system.
The vulnerability exists due to a boundary error within the Windows Kernel Cryptography Driver cng.sys, which exposes a "\Device\CNG" device to user-mode programs and supports a variety of IOCTLs with non-trivial input structures. A local user can run a specially crafted program to trigger memory corruption and execute arbitrary code on the system with elevated privileges.
Note, this vulnerability is being actively exploited in the wild.