@itm4n That's a very cool patch analysis, the detective work is crazy on this one! Also seeing an analysis of another type of vulnerability than memory corruption is very refreshing 😃
@itm4n I tried to exploit it but I'm stuck at the last step, I don't see how it is possible to do code execution by putting a 1..\..\C:foo.dll in HKLM\SYSTEM\CurrentControlSet\Services\TPM\WMI
@albinowax@infosec.exchange Interesting experiment! Did you succeed to fit all your micro inspiration in one context so that your LLM could combine them to create hypothesis?