logo

Exploit Development: Swimming In The (Kernel) Pool - Leveraging Pool Vulnerabilities From Low-Integrity Exploits, Part 2

ID: d912d6da-f49a-5014-81fb-412f36f73c7a

STIX ID: report--d912d6da-f49a-5014-81fb-412f36f73c7a

Feed Name: Connor McGarr’s Blog

Threat Score
15/100

Date Published: 2021-07-18

Date Updated: 2026-04-19

Author: Connor McGarr

...
...

Part 2 of a technical series demonstrates exploiting a NonPagedPoolNx buffer overflow in the HackSys Extreme Vulnerable Driver to achieve an arbitrary read/write primitive, leak kASLR, and bypass DEP/SMEP by corrupting page table entries, culminating in SYSTEM execution via `HalDispatchTable`; it details kLFH-based pool grooming, preserving `_POOL_HEADER` structures, abusing driver IOCTLs for read/write, resolving kernel symbols, and provides full PoC code and WinDbg-driven analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.