GithubHelp home page GithubHelp logo

brjota / kernel-exploits Goto Github PK

View Code? Open in Web Editor NEW

This project forked from arty-hlr/windows-kernel-exploitation-hevd

0.0 1.0 0.0 478 KB

Windows kernel driver exploits

Python 25.79% C++ 60.82% C 13.39%

kernel-exploits's Introduction

Windows kernel driver exploits

0day discoveries / CVEs

Various drivers included are personally discovered 0day vulnerabilities turned CVEs, each one of these has a short CVE posting and necessary links to MITRE postings, disclosure timelines, and more. Anything listed below which includes a CVE within it's description is a personally disclosed bug.

Other written exploits

Other drivers are personally developed POC exploits for drivers deemed interesting, some with unique or awesome vulnerabilities. Each driver folder will include information and references to the original 0day discovery author


AscRegistryFilter.sy

Local BSOD proof-of-concept for AscRegistryFilter.sys (CVE-2020-10234) which is a driver included within Advanced SystemCare 13.2 which is a anti-virus software from IObit. BSOD using a NULL user buffer with a 0 size. Using IOCTL 0x8001E000 tested on Windows 7 x86.

Capcom.sys

Exploits for Capcom.sys, a driver from a third-party anti-cheat software, includes a logic bug where an IOCTL disables SMEP and takes a user passed pointer. Exploits for various Windows versions.

EMP_MPAU.sys

Local BSOD DOS exploit POCs for various IOCTLs that pass data to a function that doesn't properly handle user input found within the EMP_MPAU.sys (CVE-2020-9453) driver associated with Epson's Iprojection software, multiple POCs disclosed after the vendor was contacted

EMP_NSA.sys

Local BSOD DOS exploit POCs for various IOCTLs that pass data to a function that doesn't properly handle user input found within the virtual audio device driver EMP_NSA.sys (CVE-2020-9014) driver associated with Epson's Iprojection software, multiple POCs disclosed after the vendor was contacted

Ene.sys

Includes both a local DOS POC to replicate the original author's blog post, and also includes a local privilege escalation exploit that takes advantage of a stack buffer overflow in the driver. Ene.sys comes from the ASUS Aura Sync version 1.07.71 software.

HEVD.sys

Multiple Windows kernel EOP exploits for HEVD.sys, an intentionally vulnerable driver. Exploits cover a variety of Windows kernel vulnerability classes, exploits with and without various mitigation bypasses on a few different versions of Windows.

MaxProc64.sys

Local BSOD DOS exploit POCs for MaxProc64.sys (CVE-2020-12122), a driver from a third-party "spyware detector" application

tmcomm.sys

Local BSOD DOS exploit POC for tmcomm.sys from TrendMicro RootkitBuster, multiple IOCTL calls can result in various types of writes, previously disclosed, but not patched when this POC was written

kernel-exploits's People

Contributors

fullshade avatar

Watchers

James Cloos avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.