CVE-2022-34725 is an elevation of privilege vulnerability in Windows ALPC (Advanced Local Procedure Call). The vulnerability allows a local attacker to gain elevated privileges by exploiting improper access controls or validation within the ALPC subsystem.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository purpose: a Windows local exploit research repo combining (a) a prefetch-based side-channel kernel base leak and (b) an ALPC section view use-after-free (UAF) race condition in the style of CVE-2022-38029/CVE-2022-34725, with additional ALPC message/attribute helpers and token impersonation utilities. Structure and key components: - ALPC.h: Large collection of ALPC constants, structs, enums, and NT API prototypes used throughout (NtAlpcConnectPort, NtAlpcSendWaitReceivePort, NtAlpcCreatePortSection, NtAlpcCreateSectionView, NtAlpcDeleteSectionView, NtAlpcImpersonateClientOfPort, etc.). - ViewUAF.cpp (standalone PoC): Implements the ALPC Section View UAF race. - Creates an ALPC port and port section locally (NtAlpcCreatePort + NtAlpcCreatePortSection). - Predicts the next view address by creating and deleting a section view, reusing the same ViewBase. - Spawns a high-priority racer thread that repeatedly calls NtAlpcDeleteSectionView on the predicted address while the main thread repeatedly calls NtAlpcCreateSectionView. - On a suspected win condition, performs a “kernel spray” by creating many section views to encourage reallocation/reclaim of freed pool memory. - Intended outcome is a UAF/crash/primitive observable under a debugger; it does not implement a full EoP payload. - Chain.cpp (incomplete chain): Attempts to combine a kernel base leak with an ALPC interaction against a named server port. - Calls leak_kernel_base_reliable() (from prefetch_leak.h) to print the kernel base. - setup_uaf() connects to an ALPC server port name "\\RPC Control\\CSALPCPort" (explicitly described as placeholder), creates a port section, then uses a thread intended to close/disconnect the port during subsequent ALPC operations to trigger a UAF-like condition. The implementation appears unfinished/buggy (e.g., uses closesocket on an ALPC handle; close_port uses uninitialized lSuccess). - prefetch_asm.asm + prefetch_leak.h: Implements an EntryBleed-inspired timing side-channel. - bad_syscall triggers a faulting/invalid syscall number. - sidechannel uses rdtscp + prefetch instructions to measure access timing. - leak_kernel_base_* scans a hardcoded kernel VA range and uses timing deviations to infer mapped kernel regions; includes vendor-specific routines and a “reliable” loop that repeats until two consecutive leaks match. - CommonALPC.cpp + Command.cpp + Token.cpp: Helper utilities. - Builds ALPC messages and attributes (including view attributes and handle attributes). - Provides client impersonation via NtAlpcImpersonateClientOfPort, duplicates the thread token, and can spawn a process with CreateProcessWithTokenW (hardcoded to cmd.exe). - Token.cpp prints token SID/type/impersonation level. Notable observables / fingerprintable targets: - ALPC port name: \\RPC Control\\CSALPCPort (Chain.cpp). - Spawned process path: C:\\Windows\\System32\\cmd.exe. - Sample file path used for ALPC handle attribute: C:\\Users\\Public\\testfile.txt. - Kernel VA scan bounds: 0xfffff80000000000–0xfffff80800000000. Overall assessment: - This is exploit-development PoC code (not a polished weaponized exploit). ViewUAF.cpp is the clearest, self-contained UAF race PoC. Chain.cpp suggests an intended full chain (side-channel KASLR bypass + ALPC UAF) but is marked under construction and contains incomplete/incorrect pieces.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.