CVE-2018-8897 is an x86 kernel exception-handling vulnerability caused by incorrect operating-system handling of debug exceptions deferred by the MOV SS and POP SS instructions. These instructions defer delivery of certain debug exceptions until the instruction boundary following the subsequent instruction. When that subsequent instruction transfers execution from CPL 3 to a more privileged operating-system context, such as through SYSCALL, SYSENTER, or INT3, the deferred #DB exception is delivered after the privilege transition. Affected kernels may incorrectly process the exception as though it originated in kernel context, resulting in unsafe kernel behavior. The issue affected Linux kernels and also had platform-specific consequences in Windows, macOS, FreeBSD, and some Xen configurations.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module (Ruby file) that exploits CVE-2018-8897, a privilege escalation vulnerability in Microsoft Windows (x64, except XP). The module is designed for local exploitation via an existing Meterpreter session. It supports two exploitation methods: uploading and executing a precompiled exploit binary and payload EXE, or in-memory DLL injection using a reflective DLL. The module is highly weaponized, leveraging Metasploit's payload generation and session management. It provides SYSTEM-level code execution on vulnerable systems. The code references several file paths used for payload and exploit delivery, and is configurable via module options. The structure is typical for a Metasploit local exploit, with clear separation of setup, validation, file management, and exploitation logic.
This repository is a full-featured local privilege escalation exploit for CVE-2018-8897, targeting Microsoft Windows systems vulnerable to the MOV SS and POP SS vulnerability. The exploit is implemented in C++ with critical components in x64 assembly. The main entry point is 'movss_popss.cpp', which orchestrates the attack by checking system compatibility, locating kernel modules (ntoskrnl.exe and CI.dll), resolving necessary kernel symbol offsets, and preparing the process environment. The exploit leverages two CPU cores: one to execute the exploit and another to corrupt the stack at a precise moment, enabling the attacker to hijack kernel execution flow. The assembly payload disables SMEP, steals the SYSTEM process token for privilege escalation, disables Driver Signature Enforcement (DSE), and returns to user mode with SYSTEM privileges, spawning a shell. The codebase is modular, with separate files for memory management, process manipulation, symbol resolution, and low-level hardware/OS interaction. No network endpoints are present; all actions are performed locally. The exploit is operational and includes a working payload, but is not part of a larger exploitation framework.
This repository is a proof-of-concept (PoC) exploit for CVE-2018-8897, a vulnerability in the handling of the POP SS instruction on Windows systems. The exploit is implemented in C++ with supporting assembly routines. The main exploit logic resides in Main.cpp, which orchestrates the attack by preparing kernel shellcode, manipulating processor state, and triggering the vulnerability via a crafted ROP chain and context manipulation. The payload, executed in kernel mode, escalates the current process's privileges to SYSTEM by replacing its token with that of the SYSTEM process. After successful exploitation, the code spawns a SYSTEM-level command shell (cmd.exe). The exploit requires the target to be unpatched for CVE-2018-8897 and KVA Shadowing to be disabled. The codebase is structured with several header files for kernel and memory routines, a main exploit file, and supporting assembly for low-level operations. No network endpoints are present; the attack vector is purely local privilege escalation.
This repository contains a proof-of-concept (PoC) local exploit for CVE-2018-8897, a vulnerability in the handling of the POP/MOV SS instructions on Windows systems. The exploit is implemented in C++ (movss.cpp) with a supporting assembly routine (vuln.asm). The main C++ file sets up a hardware breakpoint on the stack segment selector and invokes the assembly code to trigger the vulnerability. If the system is vulnerable, executing the exploit will cause the machine to bugcheck (crash), resulting in a local denial of service. The project is structured as a Visual Studio solution with appropriate project and filter files for building the exploit on Windows x64. No network or remote attack vectors are present; the exploit must be run locally on the target machine.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel exception-handling flaw that can cause denial of service.
A Linux kernel exception-handling vulnerability that can lead to denial of service.
A Linux kernel exception-handling vulnerability that can lead to denial of service.
An Important Linux kernel exception-handling vulnerability that can lead to denial of service.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.