What is Nostr?
James Forshaw :donor: /
npub1wp4…ejcr
2025-01-30 18:35:20

James Forshaw :donor: on Nostr: The second blog is about an interesting bug class in COM servers that implement ...

The second blog is about an interesting bug class in COM servers that implement IDispatch, which allows you to potentially create other objects in the process. For example every OOP COM server with IDispatch allows you to create a STDFONT object which isn’t really designed to be safely used cross process. To demo its usefulness I then use the trick to get code injection in a Windows-PPL process from where you could open protected LSASS etc. https://googleprojectzero.blogspot.com/2025/01/windows-bug-class-accessing-trapped-com.html
Author Public Key
npub1wp4gyc9xmkjxl0vpxpmv0hmsw25uyhvwnynewn5mrj8s66v8ku6sesejcr