CVE-2018-8611 is a local privilege escalation vulnerability in the Windows Kernel Transaction Manager (KTM). The flaw is a race-condition-driven use-after-free in TmRecoverResourceManager(), reachable from user mode via NtRecoverResourceManager(). During recovery processing, the vulnerable code iterates enlistment objects associated with a resource manager and, in the unpatched implementation, can continue using a _KENLISTMENT pointer after releasing the resource manager mutex and after conditions that allow another thread to finalize and free that enlistment. This creates a window in which a stale _KENLISTMENT pointer is dereferenced and reused after free. Public technical analysis indicates exploitation involves arranging KTM transaction, resource manager, and enlistment state so recovery notifications are issued, then racing finalization of a target enlistment to replace the freed kernel object with attacker-controlled data. Successful exploitation can yield controlled kernel memory corruption and has been shown to be transformable into kernel read/write-style primitives and ultimately SYSTEM-level privilege escalation across multiple Windows versions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a standalone C++ local privilege-escalation exploit for CVE-2018-8611, a Windows Kernel Transaction Manager (KTM) use-after-free vulnerability. It is not a framework module. The repository is small and focused: CMakeLists.txt builds a single executable from src/exploit.cpp; src/exploit.hpp contains helper macros, constants, context structures, and function declarations; src/nt.h contains large Windows kernel structure definitions and hardcoded offsets needed by the exploit; README.md documents the target CVE and the two exploitation modes. The main exploit logic lives in src/exploit.cpp. It creates KTM objects such as transaction managers, resource managers, transactions, and enlistments, then combines them with aggressive heap feng shui using large named-pipe buffers. Multiple helper routines create named pipes, events, threads, and KTM objects. The exploit spins worker threads for pipe draining and race orchestration, pins threads to CPUs, and uses congestion/recovery timing to win the KTM race and reclaim freed kernel memory with attacker-controlled data. The code clearly implements exploitation rather than detection. The README states two privilege-escalation techniques: default increment primitive and optional write-zero primitive selected with '-w'. The visible code confirms this with a global flag use_write_prim and an escalation path that either calls increment_privesc(ctx) or creates an escape enlistment and injects it to exploit a write-0 primitive against KTHREAD.PreviousMode. The hardcoded offsets in nt.h, especially KTHREAD_PreviousMode = 0x232, indicate the exploit is version-specific and tuned for Windows 10 RS5 x64. Fingerprintable endpoints are limited because this is a local exploit: the main observable artifacts are named pipes \\.\pipe\pipe0, \\.\pipe\pipe1, and \\.\pipe\spray. There are no external network URLs, IPs, or domains. Overall, the repository is an operational PoC exploit that performs local kernel heap manipulation and KTM object corruption to obtain a kernel primitive and elevate privileges on vulnerable Windows systems.
This repository contains a local privilege escalation exploit targeting Microsoft Windows 10 Consumer Edition, version 1803 (March 2018 update, x64). The main exploit logic is implemented in 'exp.cpp', which orchestrates the attack by creating a large number of named pipes to perform pool feng shui, sets up fake kernel object structures (defined in 'obj.h'), and leverages direct system calls (implemented in 'asm.asm') to interact with the Windows kernel. The exploit abuses the Kernel Transaction Manager (KTM) subsystem, manipulating resource manager and enlistment objects to achieve arbitrary kernel memory writes and ultimately escalate privileges. The code is operational and includes all necessary components to perform the attack, but is not part of a framework and does not provide a customizable payload interface. The only fingerprintable endpoint is the use of named pipes (\\.\pipe\*), which are used internally for heap manipulation. The repository is structured with one main exploit file ('exp.cpp'), a header with detailed kernel object definitions ('obj.h'), and a small assembly file for custom system calls ('asm.asm'). The exploit is intended for research or demonstration purposes on the specified Windows version.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows Kernel Transaction Manager (KTM) race condition privilege escalation vulnerability that was exploited as a 0-day in the wild to achieve kernel read/write primitives and elevate privileges.
A Windows Kernel Transaction Manager (KTM) privilege escalation vulnerability involving a race condition/use-after-free that can be exploited to build kernel read/write primitives and obtain SYSTEM privileges.
A Windows Kernel Transaction Manager (KTM) race-condition use-after-free vulnerability in TmRecoverResourceManager() involving _KENLISTMENT objects, reachable via NtRecoverResourceManager().
A Windows kernel local privilege escalation vulnerability in the Kernel Transaction Manager (KTM), described as a kernel race condition and useful as a sandbox escape in client-side exploitation scenarios.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.