Shoot The Messenger— Using Window Messages To Exploit Local Win32 Applications

No ratings

Presented at Blackhat USA 2004 by

The windows GDI interface uses messages to pass input and events to windows. As there is currently no way of determining who the sender of the message is, it is possible for a low privileged application to send messages to and interact with a process of higher privilege.