Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2010-3888

Description

Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Kaspersky Lab researchers and other researchers.

POC

Reference

- http://www.securelist.com/en/blog/2291/Myrtus_and_Guava_Episode_MS10_061

- http://www.symantec.com/connect/blogs/stuxnet-using-three-additional-zero-day-vulnerabilities

Github

- https://github.com/Cruxer8Mech/Idk

- https://github.com/ycdxsb/WindowsPrivilegeEscalation