The Windows Registry Adventure #8: Practical exploitation of hive memory corruption
ID: 1867f910-deff-52e4-a538-bb483e659498
STIX ID: report--1867f910-deff-52e4-a538-bb483e659498
Feed Name: Google Project Zero
Mateusz Jurczyk (Google Project Zero) presents an in-depth analysis of Windows registry hive memory corruption and step‑by‑step exploitation techniques targeting hive-based bugs. The report explains allocator/mapping behavior, multiple exploitation avenues (intra-hive data manipulation, pool corruption, inter-hive overflows), and details a deterministic OOB cell-index primitive to gain arbitrary kernel read/write via controlled registry values; it culminates in a proof-of-concept privilege escalation to SYSTEM on Windows 11 and discusses mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
