logo

Exploit Development: No Code Execution? No Problem! Living The Age of VBS, HVCI, and Kernel CFG

ID: 31597fdd-1811-57a4-8d96-c60ca4afc493

STIX ID: report--31597fdd-1811-57a4-8d96-c60ca4afc493

Feed Name: Connor McGarr’s Blog

Threat Score
60/100

Date Published: 2022-05-23

Date Updated: 2026-07-19

Author: Connor McGarr

...
...

# Executive Summary This detailed technical write-up explains Windows Virtualization-Based Security (VBS) and Hypervisor-Protected Code Integrity (HVCI) internals, then demonstrates a proof-of-concept exploitation technique that leverages an arbitrary kernel read/write primitive and a kernel-mode ROP chain to call arbitrary kernel APIs (enabling local privilege escalation) without executing unsigned shellcode; the PoC targets a vulnerable Dell driver (CVE-2021-21551) and includes full exploitation steps, code snippets, and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.