# CVE-2019-16098
This CVE exploits the RTCore64.sys driver and creates a cmd.exe process with system privileges by copying the token of the System process with one of the low-privilege cmd.exe process.
Blog about the approach and the methodology can be found [here](https://divyanshu-mehta.gitbook.io/researchs/windows-security-research/exploit-development/rtcore64.sys-cve-2019-16098).
[4.0K] /data/pocs/4ea107aa8ac0005ea7a8ee4504905f2d17091a33
├── [9.4K] exploit.cpp
└── [ 389] README.md
0 directories, 2 files