An elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys). Available information indicates the flaw is in the AFD.sys kernel driver and is associated with kernel-level memory-safety issues. Patch-diffing research identified the vulnerable function as AfdNotifyRemoveIoCompletion, with the fix described as a minimal code change in that routine. The vulnerability allows a local attacker to exploit the kernel component and elevate privileges on affected Windows systems.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
11 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository is a compact Windows local privilege escalation PoC for CVE-2023-21768. It contains only three files: a minimal README and two C/C++ source files (poc.cpp and poc.h). The code is not part of a larger exploit framework. The exploit chain is explicitly described in the banner as: 'AFD write primitive -> IoRing object corruption -> token replacement'. In practice, the PoC first abuses the vulnerable AFD/WinSock path by creating a socket, connecting to 127.0.0.1:135, and issuing DeviceIoControl with IOCTL 0x12127 using a crafted AFD_NOTIFY_REQUEST structure. That primitive is used to modify fields associated with an IoRing object. The code then leverages Windows IoRing functionality plus fake registered buffer entries to turn the corruption into controlled kernel read/write behavior. Named pipes (\\.\pipe\IoRingWrite and \\.\pipe\IoRingRead) are used as staging channels for the IoRing helpers. The header file defines a large amount of Windows internal structure data needed to keep offsets stable: SYSTEM_HANDLE_INFORMATION layouts, AFD_NOTIFY_REQUEST, IOP_MC_BUFFER_ENTRY, USER_IORING_CONTEXT, and a kernel IORING_OBJECT layout. It also hardcodes EPROC_TOKEN_OFFSET as 0x4b8, indicating the exploit is tuned to a specific Windows kernel layout and may fail on mismatched builds. Core capabilities visible in the code include: resolving NtQuerySystemInformation dynamically from ntdll.dll; enumerating system handles to map user handles to kernel object addresses; building fake IoRing registered buffer metadata; using pipe-backed IoRing reads/writes to access arbitrary kernel memory; locating the SYSTEM token; and overwriting the token field of a user-supplied target PID. The main entry point expects exactly one argument, a target process ID, and then runs the token swap routine. Successful exploitation yields SYSTEM privileges in the target process. Overall, this is a real exploit PoC rather than a scanner or detector. It is operational code for local EoP on vulnerable Windows systems, but it is build-sensitive and uses a fixed token offset rather than a broadly adaptable payload system.
This repository contains an operational local privilege escalation (LPE) exploit for Microsoft Windows, targeting CVE-2023-21768 (AFD IO Ring vulnerability). The exploit is written in C and is structured as a Visual Studio project, with the main logic in 'ioring_exploit.c'. The exploit works by disabling Driver Signature Enforcement (DSE) in the Windows kernel, loading an unsigned driver (by default, 'C:\Hello.sys'), and then re-enabling DSE. This allows an attacker to load arbitrary unsigned kernel drivers, which can be used for further privilege escalation or persistence. The exploit requires local access and sufficient privileges to execute. The repository is a fork and update of a previous public exploit, with enhancements to automate DSE toggling and driver loading. No network endpoints are present; the only fingerprintable endpoint is the file path for the unsigned driver. The code is mature and operational, suitable for real-world exploitation on vulnerable, unpatched Windows systems.
This repository contains a single Metasploit module implementing a local privilege escalation exploit for CVE-2023-21768, a vulnerability in the Windows Ancillary Function Driver for Winsock (afd.sys). The exploit targets Windows 11 22H2 x64 systems up to build 22621.963 (patched January 2023). The module checks the target's OS version by querying the version of ntoskrnl.exe, and only proceeds if the system is vulnerable. Upon exploitation, it injects a DLL (CVE-2023-21768.x64.dll) containing the user-supplied payload, typically a Meterpreter shell, to gain SYSTEM privileges. The exploit is weaponized, allowing customizable payloads and reliable privilege escalation on unpatched systems. The only fingerprintable endpoints are the system file ntoskrnl.exe (for version checking) and the DLL used for injection. The code is written in Ruby and is structured as a standard Metasploit local exploit module.
This repository contains a C++ proof-of-concept exploit for CVE-2023-21768, a Windows IO Ring local privilege escalation vulnerability. The exploit is designed for Windows 11 22H2 (build 22621.963) and demonstrates a full privilege escalation chain. The code is organized as a Visual Studio project with the main logic in 'WspSocket/Main.cpp', which initializes a client-server socket pair and invokes the exploit chain. The exploit uses IO Ring primitives to read and write kernel memory, locates the EPROCESS structures for the current and SYSTEM processes, and overwrites the current process's token pointer with the SYSTEM token. Named pipes (\\.\pipe\IoRingExploitInput and \\.\pipe\IoRingExploitOutput) are used for inter-process communication during the exploit. Upon success, the exploit spawns a SYSTEM-level command prompt. The code is operational and demonstrates a working local privilege escalation exploit, but is not part of a larger exploitation framework.
This repository contains a C# port of a local privilege escalation exploit for CVE-2023-21768, a vulnerability in the Windows AFD.sys driver. The exploit is designed to be compiled and executed from PowerShell, targeting a specified process ID (typically the current PowerShell process) to elevate its privileges to SYSTEM. The repository consists of a README.md with usage instructions and a single code file (eop.cs) containing the exploit logic. The exploit leverages low-level Windows kernel structures and AFD driver interactions to achieve privilege escalation. No network endpoints or remote attack vectors are present; the exploit is purely local and requires code execution on the target system. The code is a proof-of-concept and does not include weaponized or easily customizable payloads.
This repository is a local privilege escalation (LPE) exploit for CVE-2023-21768, targeting the Windows Ancillary Function Driver (AFD) and leveraging the I/O Ring kernel interface. The exploit is implemented in C and is structured as a Visual Studio project, with the main entry point in 'exploit.c'. Supporting files include 'ioring_lpe.c' (which implements the I/O Ring primitives and LPE logic), 'ioring.h', and 'win_defs.h' (which provide necessary structures and definitions). The exploit works by abusing the AFD driver's IOCTL interface and the I/O Ring kernel object to perform arbitrary kernel memory writes. It specifically targets the process token of a user-supplied PID, replacing it with the SYSTEM token, thereby granting SYSTEM privileges to the target process. The exploit requires local access and is not a remote exploit. It uses named pipes (\\.\pipe\ioring_in and \\.\pipe\ioring_out) for communication between components of the exploit. The repository is a functional proof-of-concept (POC) with operational capabilities, as it provides a working payload that can elevate privileges on vulnerable systems. The README provides usage instructions and credits, and the code is based in part on prior I/O Ring research. No network endpoints or remote attack surfaces are present; all exploitation is performed locally via kernel interfaces.
This repository implements a local privilege escalation exploit for Windows, specifically targeting CVE-2023-21768 (IoRing Local Privilege Escalation). The exploit is written in C and is structured as a Visual Studio project. The main entry point is 'nullmap/nullmap/main.c'. The exploit leverages a vulnerability in the Windows IoRing subsystem to gain arbitrary kernel read/write capabilities. It disables SMEP/SMAP by overwriting the CR4 register, allowing execution of user-mode code in kernel context. The exploit then manually maps and executes an arbitrary, user-supplied driver in kernel mode, bypassing driver signature enforcement. The exploit is operational and requires a vulnerable Windows 11 system. It interacts with kernel objects such as '\\Device\\Afd\\Endpoint' and uses named pipes for IoRing manipulation. The codebase is modular, with separate files for console output, exploit logic, IoRing manipulation, driver mapping, and utility functions. The exploit is not part of a framework and is a standalone operational exploit with a customizable payload (the driver to be mapped).
This repository contains a Visual Studio C++ project for a local privilege escalation exploit targeting CVE-2023-21768, a vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys). The exploit is designed to run on Windows 11 (version 22621.963) and leverages the afd.sys vulnerability to elevate the executing process to SYSTEM privileges. The project includes a solution file (exp.sln), project files (exp.vcxproj, .filters, .user), and references source files (exp.cpp, exp.h) which are not included in the provided content but are referenced in the project structure. The README provides links to analysis articles and screenshots demonstrating successful privilege escalation. The exploit includes cleanup code post-escalation. No network endpoints are present; the attack vector is purely local, requiring code execution on the target system. The repository is structured as a standard Visual Studio C++ project, and its primary purpose is to provide a working proof-of-concept for local privilege escalation via afd.sys on vulnerable Windows 11 systems.
This repository contains a working local privilege escalation (LPE) exploit for CVE-2023-21768, targeting the Windows I/O Ring (ioring) kernel interface. The main exploit logic is implemented in 'ioring_lpe.c', which, together with supporting headers, provides the ability to perform arbitrary kernel memory read and write operations. The exploit works by manipulating kernel structures to steal the SYSTEM process token and assign it to a user-specified process, effectively elevating that process to SYSTEM privileges. The exploit is invoked as a command-line tool, taking the PID of the target process as an argument. The code creates and interacts with named pipes (\\.\pipe\ioring_in and \\.\pipe\ioring_out) as part of its exploitation process. The repository is structured as a Visual Studio C/C++ project, with all core exploit logic in the 'CVE-2023-21768' directory. This is a fully operational exploit, not just a proof of concept, and is intended for demonstration and research purposes only.
This repository contains a working local privilege escalation (LPE) exploit for CVE-2023-21768, a vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys). The exploit is implemented in C and is structured as a Visual Studio project, with the main logic in 'LPE.c' and supporting structures in 'header.h'. The exploit works by leveraging an arbitrary kernel write vulnerability in afd.sys, specifically by interacting with the device object '\\Device\\Afd\\Endpoint' and using custom-crafted IOCTL calls to manipulate kernel memory. The exploit ultimately overwrites process token fields to elevate the current process to SYSTEM privileges. The repository includes build files, logs, and a detailed technical write-up in the readme.md, which explains the vulnerability, patch analysis, and exploitation strategy. The exploit targets unpatched Windows 11 and Windows Server 2022 systems. No network endpoints are involved; the attack vector is purely local, requiring execution on the target machine.
This repository contains a local privilege escalation exploit for CVE-2023-21768, targeting the Windows Ancillary Function Driver (AFD) via the I/O Ring subsystem. The exploit is implemented in C and is structured as a Visual Studio project, with the main logic in 'ioring_lpe.c' and supporting headers. The exploit works by abusing the I/O Ring interface to gain arbitrary read/write primitives in kernel memory, allowing it to locate the SYSTEM process's token and assign it to a user-specified process (by PID), effectively elevating that process to SYSTEM privileges. The exploit uses named pipes ('\\.\pipe\ioring_in' and '\\.\pipe\ioring_out') for internal communication. The code is operational and requires the user to specify a target process ID. The repository is a standalone proof-of-concept and not part of a larger framework. It is intended for demonstration and research purposes on vulnerable Windows systems.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A CVE referenced only in the credits as having an exploit, without substantive discussion in the article body.
A previously noted similar kernel-level memory safety vulnerability in Microsoft's AFD.sys driver, referenced for historical context only.
A local privilege escalation vulnerability in Microsoft Windows, allowing attackers to gain elevated privileges on a compromised system.
An elevation-of-privilege vulnerability affecting the Windows Ancillary Function Driver for WinSock.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.