CVE-2020-16938
Describe
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-16901
ImpactVersion
Product | Version | Update | Edition | Tested |
---|---|---|---|---|
Windows 10 | X86/x64/ARM64 | 2004 | ✔ | |
Windows Server | 2004 |
Patch
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16938
Utilization
CompilerEnvironment
- VS2019(V142)X64 Release
- VS2019(V142)X86 Release
Test system Windows 10 2004 x64
First types of use
Use the 7z GUI to view the SAM files in the Config folder, and view the UAC bomb box in the Windows folder.
Second way
Ioncodes written in EXP, I haven't understood how to do it.