CVE-2023-35080 is a vulnerability in the Ivanti Secure Access Windows client that allows a locally authenticated attacker to exploit a misconfiguration. This could result in privilege escalation, denial of service, or information disclosure. The vulnerability arises from improper enforcement of security controls in the client configuration, enabling attackers with local access to gain elevated privileges or access sensitive information.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a local privilege escalation exploit for Ivanti Secure Access (Pulse Secure) VPN client, targeting CVE-2023-35080. The exploit is implemented as both a Cobalt Strike Beacon Object File (BOF) and a standalone Windows executable (PulsePrivEsc.x64.exe). The main exploit logic is in PulsePrivEsc.c, which interacts with a vulnerable kernel driver (jnprTdi_*) to overwrite the current process token privileges, effectively granting SYSTEM-level access. The exploit requires the vulnerable driver to be running, which can be triggered by connecting to a rogue VPN server with TDI fail-over enabled (setup instructions provided in docs/SETUP_ROGUE_SERVER.md). The exploit is operational and has been tested on specific Windows 10 and 11 versions. The repository includes C header files for BOF and Windows API interaction, a Cobalt Strike Aggressor script (PulsePrivEsc.cna) to register and execute the BOF, and a Python helper for integration with other frameworks. The exploit is not a detection script and provides real privilege escalation capabilities. Notable fingerprintable endpoints include the registry path for the driver, the VPN client executable, and the driver symbolic link. The exploit is intended for use by red teamers and security professionals in controlled environments.
This repository contains a local privilege escalation exploit for CVE-2023-35080, targeting the Ivanti/Pulse VPN client kernel driver on Windows systems. The exploit is implemented in C and is structured as a Visual Studio project, with main logic in 'main.c', supporting kernel interaction in 'kernel.c', and error handling in 'error.c'. The exploit works by opening a handle to the vulnerable device (either '\\.\jnprTdi_9117_18209' for Windows 11 or '\\.\jnprTdi_9115_15819' for Windows 10), leveraging a write-what-where primitive via a specific IOCTL (0x80002018) to overwrite the SEP_TOKEN_PRIVILEGES fields in the current process token, thereby granting SYSTEM privileges. After successful exploitation, it spawns a SYSTEM-level PowerShell shell. The repository is a standalone operational exploit, not part of a larger framework, and is intended for use on systems where the vulnerable driver is present and accessible. The README provides context and references, and the code is modular, with clear separation between device interaction, kernel information gathering, and the main exploit logic.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.