CVE-2020-17087 is a local elevation of privilege vulnerability in the Windows Kernel Cryptography Driver (cng.sys). The flaw was reported in the cng!CfgAdtpFormatPropertyBlock function and is described as a vulnerability chain in which a 16-bit integer truncation causes an undersized kernel pool allocation, which then leads to an out-of-bounds write. This is consistent with an integer truncation weakness that precipitates incorrect buffer size calculation and subsequent kernel memory corruption. The vulnerability was exploited in the wild in targeted attacks prior to patching.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a comprehensive set of resources and exploit code for Windows kernel non-paged pool overflow vulnerabilities, with a primary focus on CVE-2020-17087. The structure includes: - `exploits/CVE-2020-17087.cpp`: Main exploit for CVE-2020-17087, targeting Windows 10 2004 x64. It leverages a non-paged pool overflow in the Windows kernel to achieve arbitrary read/write and escalate privileges to SYSTEM by overwriting the process token. The exploit uses named pipes and kernel structures to manipulate memory. - `exploits/vuln_driver_al20c.cpp` and `exploits/vuln_driver_all0c.cpp`: Additional exploits for custom vulnerable drivers, demonstrating similar pool overflow exploitation techniques with different overflow data (0x20 and 0x00 bytes, respectively). - `vulnerable_driver/Overfl0w.cpp` and `.inf`: Source code and installation files for a custom vulnerable driver used for local testing and exploitation. - Multiple markdown files (`.md`) provide detailed technical documentation, exploitation strategies, and background on Windows kernel pool internals and named pipe exploitation. - The repository also includes SVG diagrams illustrating heap layouts, overflow scenarios, and exploitation primitives. The main exploit is operational and weaponized for local privilege escalation on Windows 10 systems with the vulnerable driver. It is not part of a framework but is a standalone, advanced exploit with detailed documentation and supporting code for research and demonstration purposes. The primary attack vector is local, requiring execution on the target system. The exploit interacts with device interfaces such as `\\.\Overfl0w` and uses named pipes for heap manipulation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A kernel pool out-of-bounds write caused by integer truncation and undersized buffer allocation; the content states it was exploited in the wild.
A kernel pool vulnerability where integer truncation leads to undersized allocation and an out-of-bounds write; the content states it was exploited in the wild.
A zero-day local elevation of privilege vulnerability in the Windows Kernel Cryptography Driver (cng.sys) caused by a 16-bit integer truncation issue. It is significant because Google Project Zero reported it was used in targeted attacks.
A kernel pool vulnerability in which integer truncation causes undersized buffer allocation and an out-of-bounds write. The content explicitly notes it was exploited in the wild.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.