logo

The Windows Registry Adventure #8: Practical exploitation of hive memory corruption

ID: 1867f910-deff-52e4-a538-bb483e659498

STIX ID: report--1867f910-deff-52e4-a538-bb483e659498

Feed Name: Google Project Zero

Threat Score
75/100

Date Published: 2025-05-28

Date Updated: 2026-07-16

Author: Google Project Zero

...
...

Mateusz Jurczyk (Google Project Zero) presents an in-depth analysis of Windows registry hive memory corruption and step‑by‑step exploitation techniques targeting hive-based bugs. The report explains allocator/mapping behavior, multiple exploitation avenues (intra-hive data manipulation, pool corruption, inter-hive overflows), and details a deterministic OOB cell-index primitive to gain arbitrary kernel read/write via controlled registry values; it culminates in a proof-of-concept privilege escalation to SYSTEM on Windows 11 and discusses mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.