CVE-2023-38817 affects Inspect Element Ltd Echo.ac 5.2.1.0, specifically the kernel-mode component echo_driver.sys. According to the provided content, a local attacker can send a crafted command to the driver and gain elevated privileges. The issue is consistent with a vulnerable-driver / BYOVD-style abuse case in which a user-mode process interacts with the exposed driver interface to obtain kernel-assisted privilege escalation. The supplied reporting also states that the vulnerability has been used operationally to remove kernel routines used by EDR products and then escalate privileges through token theft. The vendor noted that the reported ability for user-mode applications to execute code as NT AUTHORITY\SYSTEM was allegedly "deactivated by Microsoft itself," but the content still describes the driver as exploitable for privilege escalation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This eight-file standalone C++ proof-of-concept targets CVE-2023-38817 in Echo's anti-cheat driver. The active exploit is in PoC/PrivilegeEscalation/main.cpp, supported by DriverInterface.h and DriverTypes.h, with a CMake build definition. It opens the EchoDrv device and invokes IOCTLs 0x9e6a0594, 0xe6224248, and 0x60a26124 to initialize the driver interface, obtain a high-access handle for its own process, and perform the driver-mediated memory-copy primitive. It leaks the loaded ntoskrnl base through NtQuerySystemInformation, resolves PsInitialSystemProcess, reads the SYSTEM token and walks ActiveProcessLinks to locate its own EPROCESS. It then abuses the purported read-memory operation with reversed source/destination semantics to overwrite its own Token field with the SYSTEM token. The modified PoC is explicitly post-exploitation oriented: it runs hidden Windows commands to create an administrator RDP account, enable RDP, disable NLA, and open TCP/3389. No driver binary is included; the documentation references an external driver download and SHA-256, while the root README identifies affected Echo versions and blocklist restrictions.
Repository contains a small Windows local privilege escalation exploit (2 files: main.c and DriverTypes.h). The exploit targets a vulnerable kernel driver exposed as the device \\.\EchoDrv (echo.ac/EchoDrv-style). main.c: - Discovers the kernel base address by calling NtQuerySystemInformation(SystemModuleInformation=11) and locating ntoskrnl.exe. - Opens the driver device and issues two IOCTLs: 0x9E6A0594 (initial call) and 0xE6224248 to obtain a high-privilege handle to the current process. - Implements an arbitrary kernel memory copy primitive via IOCTL 0x60A26124 (mmCopy_params), used as both read and write. - Loads ntoskrnl.exe in user mode to compute the RVA of PsInitialSystemProcess, then reads the kernel pointer at kernelBase+RVA to obtain the SYSTEM EPROCESS. - Reads SYSTEM’s token from EPROCESS+0x4B8 (hardcoded for Win10 22H2) and overwrites the current process token, yielding SYSTEM privileges. - Spawns C:\Windows\System32\cmd.exe and then hides that cmd process by reading its EPROCESS pointer (via SystemExtendedHandleInformation=64 handle table walk) and unlinking its ActiveProcessLinks (offset 0x448) from the global process list (DKOM). DriverTypes.h provides supporting structs for IOCTL parameter blocks and NT system information/handle enumeration structures. No network activity is present; the primary fingerprintable target is the local device name \\.\EchoDrv and the specific IOCTL codes used.
This repository is a C++ project that implements a local privilege escalation exploit for Windows systems by leveraging a vulnerable signed driver (CVE-2023-38817). The exploit is structured as a Visual Studio solution with source and header files under the 'kur' directory. The main class, 'kur_t', encapsulates all exploit functionality, including installing the vulnerable driver, setting up the necessary registry keys, loading and unloading the driver, and interacting with it via IOCTLs. The exploit provides two main capabilities: (1) arbitrary kernel-mode read/write of user-mode memory using the driver's exposed MmCopyVirtualMemory functionality, and (2) obtaining process handles with arbitrary access directly from kernel mode, bypassing standard access checks. The code handles driver installation by writing the driver file to the system's temporary directory and creating the appropriate registry entries under 'SYSTEM\CurrentControlSet\Services'. It then loads the driver using native Windows APIs and communicates with it via DeviceIoControl calls. The exploit is not weaponized for remote or automated attacks but provides operational-level primitives for local privilege escalation and memory manipulation. No hardcoded IP addresses or network endpoints are present; all endpoints are local file paths and registry keys related to driver installation and operation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability in the Echo.ac anti-cheat driver for Minecraft that was abused by RealBlindingEDR to disable or blind EDR protections and facilitate privilege escalation via token theft.
A vulnerability in the Echo.ac Minecraft anti-cheat driver that was abused by attackers via RealBlindingEDR to disable or blind EDR protections and escalate privileges through token theft.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.