CVE-2020-0668 is an elevation of privilege vulnerability in the Windows Kernel, caused by improper handling of objects in memory. An attacker who successfully exploits this vulnerability could execute code with elevated privileges. The vulnerability is triggered when the Windows Kernel fails to properly handle certain objects, allowing a local attacker to gain SYSTEM-level access.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module implementing a local privilege escalation exploit for CVE-2020-0668, targeting Windows 10 x64 systems (builds 17134-18363). The exploit abuses a trusted file overwrite and DLL hijacking vulnerability in the Windows Service Tracing feature. The module works by modifying specific registry keys (notably under HKLM\SOFTWARE\Microsoft\Tracing), dropping a malicious DLL (WindowsCreDeviceInfo.dll) into a controlled directory, and triggering the vulnerable code path via the RASDIAL utility and a crafted phonebook file. The default payload is a Meterpreter reverse shell, but any compatible payload can be used. The exploit requires an existing Meterpreter session on the target and is only effective on 64-bit Windows 10 systems within the specified build range. The code is operational and provides SYSTEM-level access if successful. The structure is typical for a Metasploit local exploit module, with clear separation of setup, exploitation, and cleanup routines.
This repository is a C# proof-of-concept exploit for CVE-2020-0668, a Windows Service Tracing Elevation of Privilege vulnerability. The main exploit logic is implemented in Program.cs, which leverages the NtApiDotNet library to create symbolic links in the \RPC Control object directory and manipulates the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RASTAPI to redirect tracing output. By doing so, it enables an arbitrary file move operation with SYSTEM privileges. The exploit writes a temporary phonebook file and triggers the vulnerable behavior using the 'rasdial' utility. The exploit does not directly provide a shell or code execution, but it can be used as a primitive for privilege escalation (e.g., by moving a malicious DLL to a privileged location). The repository includes standard Visual Studio project files, resource files, and a sample phonebook configuration. The README provides usage instructions and references to further privilege escalation techniques that can be combined with this exploit.
This repository contains a multi-version exploit for CVE-2020-0668, a local privilege escalation vulnerability in Microsoft Windows 10. The exploit is divided into several components: - **Diaghub_Exploit/exp.ps1**: A PowerShell script for Windows 10 versions < v1903. It manipulates the registry and creates symbolic links to redirect tracing output, allowing a malicious DLL (evil.dll) to be written to C:\Windows\System32\ and executed as SYSTEM. The payload can be generated with msfvenom and can perform actions such as adding a user. - **UsoDllLoader_Exploit/exp.ps1**: A PowerShell script for Windows 10 versions >= v1903. It performs similar actions as the Diaghub exploit but targets WindowsCoreDeviceInfo.dll. The exploit results in the DLL being loaded as SYSTEM, which then spawns a bind shell on 127.0.0.1:1337. - **SysTracingPoc-Release/**: Contains C++ source code for building the core exploit logic, utilities for manipulating symbolic links, registry keys, and file operations. The SysTracingExploit and SysTracingPoc executables automate the exploitation process, including service checks (RasMan, IKEEXT), DLL placement, and cleanup. - **UsoDllLoader/** and **WindowsCoreDeviceInfo/**: Contain the code for the payload DLL and the loader. The payload DLL (WindowsCoreDeviceInfo.dll) implements a bind shell on port 1337, granting SYSTEM-level access to the attacker. - **README.md**: Provides detailed usage instructions for each exploit variant, including payload generation and execution steps. The exploit requires local access and leverages symbolic link and registry manipulation to escalate privileges. The main attack vector is local, and the result is a SYSTEM shell or arbitrary command execution. The repository is mature, providing both proof-of-concept and operational payloads, and is not part of a known exploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.