�@Microsoft��Google���܂ރe�N�m���W�[�����̑������Ƃ́AAI�C���t���̊g�[���������i�ɑ����G�[�W�F���g�@�\�̒lj��A���Ƃւ̓����x���̂��߂ɐ��\���h���𓊂��Ă����B�����ɂ��������炸�A2025�N�̏I���肪�߂Â����錻�݂ɂ����Ă��AAI�̉��l���\���Ɉ����o�����Ƃ͈ˑR�Ƃ��Ċ��Ƃ̉ۑ��ƂȂ��Ă����B
Go to technology
,更多细节参见safew官方下载
└──────────┬────────────┘
The key is the test TST_SEL_RET on line 682. It compares the RPL of the return CS selector (saved on the stack by the original CALL) against the current CPL. If RPL == CPL, the PLA returns 0x000 (continue) and LD_DESCRIPTOR finishes normally -- same-privilege return. If RPL CPL, the caller is returning to a less-privileged ring, so the PLA redirects to 0x686 (RETF_OUTER_LEV) -- the cross-privilege path that must also restore the caller's stack. If RPL