POC2021 – Pwning the Windows 10 Kernel with NTFS and WNF Slides
ID: 1451fd9b-7b3e-5f27-84bf-193d603db8a1
STIX ID: report--1451fd9b-7b3e-5f27-84bf-193d603db8a1
Feed Name: NCC Research
Threat Score
Alex Plaskett's POC 2021 talk "Pwning the Windows 10 Kernel with NTFS and WNF" analyzes CVE-2021-31956, a local privilege escalation 0day reportedly exploited in the wild. The presentation walks through assessing exploitability on modern Windows (including the Segment Heap), leveraging the Windows Notification Framework (WNF) to build exploit primitives, challenges for reliable kernel pool exploitation, and lessons to aid detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
