Skip to content

Team-Byerus/CVE-2023-51000

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 

Repository files navigation

AppCheck - arbitrary file write to lpe

image

POC.mp4

Vulnerabilities occur in all user environments that attempt to install the latest version of AppCheck. In the process of running the installation anti-virus process level at "High" or higher, folders that can be accessed by regular users are read/written, and a symbolic vulnerability (lace condition) is used to arbitrarily access folders that require the same permissions as the System32 folder with regular user permissions. File writing is possible. So the attacker indiscriminately distributes it in advance, waits for the user to install AppCheck, and then the vulnerability is triggered upon installation.

Credit Information

Team Byerus (HeeChan Kim, Jinyoung Kim, MinkUk Kim, Seoungjin, Oh, Sangsoo Jeong)

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published