logo

zer0pts CTF 2022 kRCE writeup: Limited Userland Interface to Kernel RCE

ID: 6345c695-757c-5c9b-a8d6-ea8f20f07599

STIX ID: report--6345c695-757c-5c9b-a8d6-ea8f20f07599

Feed Name: Will's Root

Threat Score
30/100

Date Published: 2022-03-20

Date Updated: 2026-04-19

Author: Unknown

...
...

This writeup documents kRCE, a zer0pts CTF 2022 kernel challenge: the author analyzes the userland interface and vulnerable kernel driver, discovers negative indexing and arbitrary kernel heap read/write, uses a module-data leak to bypass KASLR, builds arbitrary read/write primitives, and constructs a kernel ROP chain to mprotect and copy shellcode into the user process to obtain a shell; full PoC C and pwntools exploits are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.