Win 7, Server 2008 'Total Meltdown' exploit lands, pops admin shells • The Register
Create a new set of page tables which will allow access to any physical memory address;
Create a set of signatures which can be used to hunt for _EPROCESS structures in kernel memory;
Find the _EPROCESS memory address for our executing process, and for the System process; and
Replace the token of our executing process with that of System, elevating us to NT AUTHORITY\System.
microsoft  meltdown  vulnerability  exploit  xen 
april 2018 by bwiese

