logo

Exploit Development: Swimming In The (Kernel) Pool - Leveraging Pool Vulnerabilities From Low-Integrity Exploits, Part 1

ID: 1b71b2d5-f918-5cda-98e1-b9c1abe32afb

STIX ID: report--1b71b2d5-f918-5cda-98e1-b9c1abe32afb

Feed Name: Connor McGarr’s Blog

Threat Score
30/100

Date Published: 2021-06-07

Date Updated: 2026-04-19

Author: Connor McGarr

...
...

This post analyzes Windows kernel pool internals (segment heap/kLFH) and demonstrates exploiting an out-of-bounds read in the HackSys Extreme Vulnerable Driver (HEVD) to leak adjacent pool data and bypass kASLR from a low-integrity process. Through pool grooming with CreateEvent objects and targeted allocation of a 0x70-byte structure containing a function pointer, the author reliably discloses kernel addresses and derives the HEVD base without restricted APIs, providing detailed WinDbg traces and PoC code.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.