Hacker News new | ask | show | jobs
by worthless-trash 909 days ago
Can you explain how..

Its my understanding that if "OS process" runs with its own address space with privileges (as it needs to talk to hardware), once an attacker has code execution functionality, what stops them from mapping the memory they need then writing to the address to set uid ?