logo

The Windows Registry Adventure #6: Kernel-mode objects

ID: f6c8b580-686b-52ea-9ba9-fedc630247c1

STIX ID: report--f6c8b580-686b-52ea-9ba9-fedc630247c1

Feed Name: Google Project Zero

Threat Score
30/100

Date Published: 2025-04-16

Date Updated: 2026-07-16

Author: Google Project Zero

...
...

This is an in-depth technical analysis of Windows Registry kernel internals (HHIVE/CMHIVE, view maps, cell maps, KCBs, transactions, layered/differencing hives) that documents structure layouts, memory-mapping and synchronization behavior, and highlights security-relevant implementation details and historical vulnerabilities (several CVEs). The author explains how these internals affect reliability and security (e.g., page residency, CoW vs locked pages, small-dir optimization) and points out exploitation primitives and past bugs without reporting an ongoing attack.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.