CVE-2023-36802 is a Windows local privilege escalation vulnerability in the Microsoft Kernel Streaming Service driver, mskssrv.sys. The flaw is caused by a type confusion between FSContextReg and FSStreamReg objects in the driver’s rendezvous/stream handling logic. An object stored in FileObject->FsContext2 can be initialized as an FSContextReg object, but later code paths such as FSRendezvousServer::PublishTx, PublishRx, ConsumeTx, or ConsumeRx may treat that object as an FSStreamReg instance. Because FSContextReg is smaller and not derived from FSStreamReg, this confusion leads to out-of-bounds access when FSStreamReg methods dereference fields beyond the bounds of the actual allocation. Public analysis describes a trigger path in which InitializeContext creates the smaller object and a subsequent publish/consume operation reaches vulnerable logic. The patch reportedly tightened object validation so only FSStreamReg objects of the expected type are accepted. The vulnerability was reported as actively exploited and can be used to escalate from a local user context to SYSTEM.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a small Windows local kernel exploit PoC for CVE-2023-36802, with two variants: a minimal crash trigger under crash/ and a larger exploitation-oriented PoC in the repository root. README only names the CVE. The crash variant consists of crash/head.h and crash/poc.cpp and simply opens the target device, sends IOCTL_FRAMESERVER_INIT_CONTEXT followed by IOCTL_FRAMESERVER_PUBLISH_RX with crafted buffers, likely to reproduce a crash or basic corruption. The main exploit is implemented in head.h and poc.cpp. head.h contains most helper logic and exploit primitives: device-opening code, custom IRP and DATA_QUEUE_ENTRY structures, fake queue entry construction, named-pipe scanning, a kernel memory read primitive built around PeekNamedPipe on corrupted pipe queue metadata, and kernel structure offsets for EPROCESS/ETHREAD traversal. poc.cpp performs the exploitation workflow: opens the vulnerable device twice, allocates controlled memory at a fixed user address, prepares fake DATA_QUEUE_ENTRY/IRP objects, sprays named pipes to shape kernel pool allocations, creates holes, issues IOCTL_FRAMESERVER_INIT_CONTEXT to place a vulnerable object into reclaimed memory, refills holes with overlapped writes, and triggers IOCTL_FRAMESERVER_PUBLISH_RX asynchronously to corrupt pipe structures while keeping the thread alive. After corruption, the exploit scans sprayed pipes to identify a victim pipe containing a marker, recalibrates offsets dynamically, and uses ReadMem to read arbitrary kernel memory through the corrupted pipe queue entry. It then reads linked kernel objects to recover an IRP pointer, ETHREAD, current process, and locate the SYSTEM process by walking ActiveProcessLinks. The provided content stops after locating SYSTEM, so the final privilege-escalation write primitive or token swap is not visible here, but the exploit clearly aims at local kernel privilege escalation. Overall, this is a real local Windows kernel exploit PoC with pool grooming and kernel read capabilities, not merely a detector.
This repository contains a functional local privilege escalation (LPE) exploit for CVE-2023-36802, a type confusion vulnerability in the Microsoft Kernel Streaming Server driver (mskssrv.sys) on Windows 11 22H2 (OS Build 22621.1631). The exploit is implemented in C and consists of several source and header files, with the main entry point being 'POC/exploit.c'. The exploit works by heap spraying with named pipes to groom kernel memory, leaking kernel addresses to bypass KASLR, and ultimately overwriting the attacker's process token with the SYSTEM token by exploiting the out-of-bounds write in the driver. The exploit requires a process PID as input and, if successful, elevates that process to SYSTEM privileges. The repository also includes detailed analysis and explanation of the vulnerability and exploitation technique in 'analysis.md' and 'readme.md'. The exploit is operational and demonstrates a full privilege escalation chain, but is not part of a larger exploitation framework.
This repository contains a local privilege escalation (LPE) exploit for CVE-2023-36802, targeting the Microsoft Kernel Streaming Service (MSKSSRV) on Windows 11 22H2. The exploit is implemented in C and is structured as a Visual Studio project. The main exploit logic resides in 'exploit.c', which orchestrates kernel memory spraying, object pointer retrieval, and the use of the IoRing interface to manipulate kernel structures. Supporting files include 'ioring_lpe.c' (IoRing setup and LPE logic), 'ioring.h' (IoRing structure definitions), and 'windefs.h' (Windows kernel structure definitions). The exploit requires the user to specify a process ID, which it then attempts to elevate to SYSTEM privileges by stealing the SYSTEM process token. Several fingerprintable endpoints are used, including named pipes (\\.\pipe\innocent, \\.\pipe\ioring_in, \\.\pipe\ioring_out) and a device path for the vulnerable driver. The exploit is operational and demonstrates a working LPE on vulnerable systems, but may require adaptation for other Windows versions.
This repository contains a working local privilege escalation exploit for CVE-2023-36802, targeting the MSKSSRV.SYS driver on Windows 10 and 11. The main exploit logic is implemented in 'exploit.c', which interacts directly with the vulnerable driver using custom IOCTL codes and kernel memory manipulation. The exploit performs heap spraying using named pipes (\\.\pipe\exploitpipe), leaks kernel object addresses, and ultimately overwrites the current process token with the SYSTEM token. Upon success, it spawns a SYSTEM shell (cmd.exe). The code is structured as a Visual Studio C/C++ project, with supporting header and project files. The exploit is operational and demonstrates a full privilege escalation chain, but is not part of a larger exploitation framework.
This repository is a proof-of-concept (PoC) exploit for CVE-2023-36802, a local privilege escalation vulnerability in the Microsoft Kernel Streaming Service (MSKSSRV.sys) on Windows 11 22H2 22621.1848. The exploit is implemented in C and consists of two main code files: 'Source.c' (main exploit logic) and 'Types.h' (type definitions and Windows structures). The exploit interacts directly with the vulnerable device driver via a specific device path, leveraging type confusion to manipulate kernel memory structures. Upon successful exploitation, it spawns a SYSTEM-level command shell (cmd.exe), granting the attacker full administrative privileges. The exploit requires local code execution on a vulnerable system and does not target remote or network attack vectors. The repository is structured for research and demonstration purposes, referencing public write-ups and prior research. No fake or destructive code is present, and the exploit is not part of a larger framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A local privilege escalation vulnerability in Microsoft Windows, allowing attackers to gain elevated privileges on a compromised system.
Microsoft Streaming Service vulnerability (separate from June 2024 issues) explicitly noted as exploited in the wild.
A Windows Kernel local privilege escalation vulnerability in the mskssrv.sys driver caused by type confusion leading to out-of-bounds access, which can be exploited to gain SYSTEM privileges.
A Windows kernel/local privilege escalation vulnerability referenced as another step in the broader exploit chain, not the main focus of this article.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.