logo

Windows Exploitation Tricks: Trapping Virtual Memory Access (2025 Update)

ID: 9ae77281-b68d-5a72-af28-59d566afce7e

STIX ID: report--9ae77281-b68d-5a72-af28-59d566afce7e

Feed Name: Google Project Zero

Date Published: 2025-01-30

Date Updated: 2026-04-27

Author: Google Project Zero

...
...

The post explains that Windows 11 24H2 now allows specifying a custom TCP port for the SMB client (via `net use ... /TCPPORT:`), enabling attackers and researchers to run a fake SMB server locally without admin privileges. This change makes it easier to create virtual memory access traps and locally exploit TOCTOU and “False File Immutability” vulnerabilities, removing the need for remote servers or the Cloud Filter API, though it can be disabled by Group Policy.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.