|
|
Windows kernel: use-after-free with UserCommitDesktopMemory | |||||
| Reported by cevans@google.com, Apr 17 2015 | Back to list | |||||
Credit is to "Nils Sommer of bytegeist, working with Google Project Zero". I reproduced the blue screen immediately in my Win 7 32-bit VM. --- Freed memory is accessed after switching between two desktops of which one is closed. The testcase crashes with and without special pool enabled. The attached crash output is with special enabled on win32k.sys and ntoskrnl.sys. --- This bug is subject to a 90 day disclosure deadline. If 90 days elapse without a broadly available patch, then the bug report will automatically become visible to the public.
Comment 1
by
cevans@google.com,
Apr 17 2015
,
Apr 23 2015
,
Apr 24 2015
,
Jul 17 2015
,
Jul 17 2015
Fixed in MS15-073
,
Sep 21 2015
|
||||||
| ► Sign in to add a comment | ||||||