The ene.sys driver in G.SKILL Trident Z Lighting Control (up to version 1.00.08) exposes critical hardware-level operations such as mapping/unmapping physical memory, direct MSR access, and I/O port operations to local non-privileged users. This insecure exposure allows attackers to perform arbitrary kernel-level actions, leading to privilege escalation to SYSTEM.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact Windows local privilege escalation exploit consisting of a single C++ source file (gROOT.cpp), a short README, and a license. The exploit targets CVE-2020-12446 through a vulnerable signed driver exposed as \\.\GLCKIo. Its core capability is arbitrary physical memory access by invoking IOCTL 0x80102040 to map a very large portion of physical memory into the attacker-controlled process. Once mapped, the code manually walks x64 page tables to translate virtual kernel addresses to physical addresses. The exploit is tailored to Windows 11 24H2 x64 using hardcoded kernel structure offsets such as EPROCESS token offset, ActiveProcessLinks-related offsets, PsInitialSystemProcess offset, and halpLMStub offset; a commented alternative offset suggests partial support for Windows 11 25H2 x64 if adjusted. After obtaining access to physical memory, the exploit locates kernel structures, identifies the SYSTEM process EPROCESS, traverses the active process list to find the current process, reads the SYSTEM token, and overwrites the current process token with that privileged token. It then executes system("cmd") to spawn a SYSTEM shell. Repository structure is minimal and purpose-built: README.md identifies the CVE and links to a write-up, while gROOT.cpp contains all exploit logic including driver interaction, memory mapping, virtual-to-physical translation, process list traversal, token stealing, and shell launch. There are no networking components, C2 features, persistence mechanisms, or modular payload options. This is an operational local exploit PoC with a hardcoded post-exploitation action rather than a reusable framework module.
Repository purpose: a Windows local privilege escalation (LPE) exploit that abuses a vulnerable kernel driver exposing physical-memory mapping primitives (device \\.\GLCKIo; WinIO-style IOCTLs) to perform token stealing and obtain SYSTEM. High-level exploit flow (as implemented/described): - Opens the vulnerable driver device and maps (near) all physical memory into user space using IOCTL_WINIO_MAPPHYSTOLIN (0x80102040). Unmaps with IOCTL_WINIO_UNMAPPHYSADDR (0x80102044). - Leaks the kernel address of SYSTEM’s EPROCESS by: - Opening a handle to PID 4 (OpenProcess(PROCESS_QUERY_LIMITED_INFORMATION, ..., 4)). - Calling NtQuerySystemInformation(SystemHandleInformation=0x10) to enumerate handles and find the entry matching the current PID and the handle value, then reading the associated Object pointer (kernel EPROCESS address). - Builds a virtual-to-physical translation map using the Superfetch PFN query technique (NtQuerySystemInformation(SystemSuperfetchInformation=79) with SuperfetchMemoryRangesQuery and SuperfetchPfnQuery). This avoids needing to leak CR3 and walk page tables. - Translates the leaked SYSTEM EPROCESS virtual address to a physical address, then reads SYSTEM’s token from physical memory at EPROCESS_TOKEN_OFFSET (0x4B8) and masks low bits. - Walks the ActiveProcessLinks list starting from SYSTEM’s EPROCESS (offset 0x448) until it finds the current process by PID (offset 0x440), then locates the current process token pointer. - Overwrites the current process token with SYSTEM’s token in the mapped physical memory region, effectively elevating the process to SYSTEM. - Spawns a shell (system("cmd.exe"); README claims PowerShell, but code shows cmd.exe). Targeting notes: - Hardcoded EPROCESS offsets are explicitly labeled for Windows 11 21H2, making the exploit version-dependent. - This is a local exploit (no network IOCs). The key fingerprintable target is the driver device name \\.\GLCKIo and the specific IOCTL codes. Repository structure: - main.cpp: exploit entry point; driver open/map, SYSTEM EPROCESS leak via handle table, Superfetch-based translation, token stealing, shell spawn. - DeviceIO.h: driver interaction helpers (CreateFileW/DeviceIoControl) and constants (device path, IOCTLs, EPROCESS offsets). - superfetch.h + superfetchNT.h: implementation of Superfetch PFN querying to cache virtual->physical translations; privilege enabling via RtlAdjustPrivilege. - Visual Studio project/solution files (.sln/.vcxproj/.filters) for building x86/x64. - README.md: step-by-step description and sample output demonstrating SYSTEM escalation.
This repository contains a local privilege escalation (LPE) exploit targeting Windows 11 24H2 x64 systems with the vulnerable eneio64.sys driver (CVE-2020-12446). The main code file, LPEeneio64.cpp, implements the exploit logic in C++. It interacts directly with the device driver via the device name \\.\GLCKIo and leverages a specific IOCTL (0x80102040) to map physical memory. The exploit locates the SYSTEM process token in kernel memory and overwrites the current process's token, effectively granting SYSTEM privileges. Upon success, it spawns a SYSTEM shell (cmd.exe). The repository is structured simply, with a single exploit source file, a README describing the target and purpose, and a license file. No network endpoints are involved; the attack vector is purely local, requiring execution on the target machine with access to the vulnerable driver.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.