Windows Escalate NtUserLoadKeyboardLayoutEx Privilege Escalation | Metasploit Exploit Database (DB)

Windows Escalate NtUserLoadKeyboardLayoutEx Privilege Escalation

This module exploits the keyboard layout vulnerability exploited by Stuxnet. When processing specially crafted keyboard layout files (DLLs), the Windows kernel fails to validate that an array index is within the bounds of the array. By loading a specially crafted keyboard layout, an attacker can execute code in Ring 0.

Search Other Modules


Rank

  • Normal

Authors

  • Ruben Santamarta < >
  • jduck < jduck [at] metasploit.com >

Vulnerability References


Development


Similar Modules


Usage Information

$ msfconsole

                ##                          ###           ##    ##
 ##  ##  #### ###### ####  #####   #####    ##    ####        ######
####### ##  ##  ##  ##         ## ##  ##    ##   ##  ##   ###   ##
####### ######  ##  #####   ####  ##  ##    ##   ##  ##   ##    ##
## # ##     ##  ##  ##  ## ##      #####    ##   ##  ##   ##    ##
##   ##  #### ###   #####   #####     ##   ####   ####   #### ###
                                      ##

msf > use post/windows/escalate/ms10_073_kbdlayout
msf post(ms10_073_kbdlayout) > set SESSION [INTEGER]


Module Options

SESSION The session to run this module on.
VERBOSE Enable detailed status messages
WORKSPACE Specify the workspace for this module