Exploit Development: No Code Execution? No Problem! Living The Age of VBS, HVCI, and Kernel CFG
ID: 31597fdd-1811-57a4-8d96-c60ca4afc493
STIX ID: report--31597fdd-1811-57a4-8d96-c60ca4afc493
Feed Name: Connor McGarr’s Blog
# Executive Summary This detailed technical write-up explains Windows Virtualization-Based Security (VBS) and Hypervisor-Protected Code Integrity (HVCI) internals, then demonstrates a proof-of-concept exploitation technique that leverages an arbitrary kernel read/write primitive and a kernel-mode ROP chain to call arbitrary kernel APIs (enabling local privilege escalation) without executing unsigned shellcode; the PoC targets a vulnerable Dell driver (CVE-2021-21551) and includes full exploitation steps, code snippets, and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
