Exploiting Windows KTM Part 4/5
ID: b200cd30-55f5-5712-8f21-929e438ad399
STIX ID: report--b200cd30-55f5-5712-8f21-929e438ad399
Feed Name: NCC Research
This report details a kernel-level exploitation path in the Windows KTM subsystem: by crafting fake userland KENLISTMENT/KMUTANT structures and abusing the recovery thread in TmRecoverResourceManager(), the authors leak kernel pointers, create a Limited Write Primitive (an increment primitive via KeReleaseMutex/KiTryUnwaitThread), and combine it with an arbitrary kernel read (NtQueryInformationResourceManager) to perform a local privilege escalation to SYSTEM. The writeup explains required structure layouts, exploitation steps, limitations across Windows versions, and operational caveats (stability risks, performance), and demonstrates a proof-of-concept on an unpatched Windows 10 build.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
