NTFS Remote Code Execution (CVE-2020-17096) Analysis
This is an analysis of the CVE-2020-17096 vulnerability published by Microsoft on December 12, 2020. The remote code execution vulnerability assessed with Exploitation: “More Likely”, grabbed our attention among the last Patch Tuesday fixes. Diffing ntfs.sys Comparing the patched driver to the unpatched version with BinDiff, we saw that there’s only one changed function, NtfsOffloadRead. …
NTFS Remote Code Execution (CVE-2020-17096) Analysis Read More »