A vulnerability in the Windows drivers wfshbr64.sys and wfshbr32.sys allows a local attacker to send specially crafted IOCTL requests, enabling arbitrary code execution with elevated privileges. The flaw exists due to insufficient validation of user-supplied data in IOCTL handlers, permitting local privilege escalation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (PoC) exploit for CVE-2022-42046, a local privilege escalation vulnerability in the wfshbr64.sys and wfshbr32.sys Windows drivers. The exploit is implemented in both C++ (EvilWfshbr/EvilWfshbr.cpp) and Rust (wfsexploit/src/main.rs), providing both a basic and a feature-rich CLI version. The vulnerability allows an unprivileged local user to perform arbitrary bitwise operations on the EPROCESS structure of their own process by sending crafted IOCTL requests to the driver, thereby elevating the process to a protected status (e.g., CodeGen Full protection). The exploit interacts with the driver via device handles (e.g., \\.\htsysm7F34) and uses specific IOCTL codes to manipulate process protection flags. The repository includes test code for structure alignment and magic value generation, as well as documentation and build files. The exploit is not weaponized but provides a working PoC for local privilege escalation on systems with the vulnerable driver loaded.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.