Headline
Windows LSA Service LsapGetClientInfo Impersonation Level Check Privilege Escalation
On Microsoft Windows, the LsapGetClientInfo API in LSASRV will fallback and directly capture a caller’s impersonation token if it fails to impersonate, leading to elevation of privilege if the impersonation level is not checked.
© 2022 Packet Storm. All rights reserved.