exploit remote desktop drv

termdd.sys support kb4499175

test environment

win7 x64 7601
Uac(Closed) LoadDriverPoc debug x64

how to test

Demonstrated the use of this vulnerability to load unsignature drivers
LoadDriverPoc.exe termddsysName UnsignatureDriverName
LoadDriverPoc.exe OldTermdd.sys TestDrvNoSig.sys(Load)
LoadDriverPoc.exe TestDrvNoSig.sys(Unload)

1.No worth
2.need uac bypass
3.any address read and write

Analysis report: https://bbs.pediy.com/thread-252411.htm