CVE-2024-26229 is a local elevation-of-privilege vulnerability in the Windows Client Side Caching driver, csc.sys. Available technical reporting characterizes the flaw as arising from improper address validation in an IOCTL handler that uses METHOD_NEITHER, while Microsoft classifies the issue as a heap-based buffer overflow. The vulnerability is reachable from a low-privileged local context and can be exploited in kernel context through crafted I/O control requests to the CSC service driver. Public research indicates the flaw can be used to obtain powerful kernel memory primitives, including arbitrary or near-arbitrary kernel read and write capabilities, which can then be leveraged to elevate privileges to SYSTEM.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a compact Cobalt Strike Beacon Object File implementation of CVE-2024-26229, a local privilege escalation vulnerability in the Windows CSC driver. The repository contains three files: a README with usage/targeting notes, a large generic beacon.h BOF API header, and the main exploit source cve-2024-26229.c. Because this is framework-oriented BOF code, the operative exploit logic is concentrated in cve-2024-26229.c. The exploit is local-only and does not perform remote exploitation or built-in network communication. Its core capability is to elevate the current Beacon process to SYSTEM. It does this by opening the CSC device path \\Device\\Mup\\;Csc\\.\\. with NtCreateFile, then issuing NtFsControlFile with IOCTL 0x001401a3 (CSC_DEV_FCB_XXX_CONTROL_FILE) and a crafted pointer so the vulnerable driver corrupts KTHREAD->PreviousMode. Once PreviousMode is changed from UserMode to KernelMode, the BOF uses NtWriteVirtualMemory to write to kernel memory. It enumerates system handles via NtQuerySystemInformation(SystemHandleInformation) to recover kernel object pointers for the SYSTEM EPROCESS (PID 4), the current KTHREAD, and the current EPROCESS. It then performs DKOM token theft by copying the SYSTEM process token from sysproc+0x4B8 to curproc+0x4B8. Finally, it restores PreviousMode to UserMode and optionally launches an operator-supplied executable with CreateProcessA using the newly inherited SYSTEM token. The exploit is operationally useful inside a C2 workflow: it accepts two BOF-packed string arguments (path and args), prints status back through BeaconPrintf, and can spawn an arbitrary child process as SYSTEM with CREATE_NO_WINDOW. The README also notes that even if process creation fails, the Beacon process itself remains elevated after token replacement. Hardcoded offsets make it version-specific: EPROCESS->Token = 0x4B8 and KTHREAD->PreviousMode = 0x232, matching Windows 10 19041–19045 and Server 2019 17763 on x64. The CSC driver must be enabled, documented via HKLM\SYSTEM\CurrentControlSet\Services\CSC Start=1. Overall, this is a real BOF exploit for post-exploitation privilege escalation, not a scanner or detection script.
Small standalone Windows local privilege escalation repository containing one real exploit source file and a minimal README with a build command (`cl.exe exploit.c /link ntdll.lib`). The code is a native C exploit that dynamically resolves NT APIs from ntdll.dll, opens the device path `\\Device\\Mup\\;Csc\\.\\.`, and issues `NtFsControlFile` with control code `0x001401a3` to reach a vulnerable CSC/MUP kernel path. It then uses `NtQuerySystemInformation(SystemHandleInformation)` to map user handles to kernel object addresses, locating the SYSTEM EPROCESS (PID 4, handle 4), the current thread object, and the current process EPROCESS. With hardcoded kernel offsets, it abuses the vulnerability to alter `KTHREAD.PreviousMode`, enabling `NtWriteVirtualMemory` to act as an arbitrary kernel write primitive. The exploit copies the SYSTEM token from the SYSTEM EPROCESS into the current process token field, restores PreviousMode to UserMode, and finally launches `cmd.exe`, yielding a SYSTEM shell. Repository structure is minimal: one README and one C source file; purpose is clearly local Windows kernel privilege escalation rather than detection or scanning.
This repository contains a Nim implementation of a local privilege escalation (LPE) exploit for CVE-2024-26229, a vulnerability in the Windows Client Side Caching (CSC) driver. The exploit targets unpatched Windows 10 and 11 systems. The repository consists of two files: a README.md with usage instructions and background, and main.nim, which contains the exploit logic. The exploit works by abusing the CSC device object (\\Device\\Mup\\;Csc\\.\\.) to manipulate kernel structures and escalate privileges to SYSTEM. After successful exploitation, it executes an arbitrary PowerShell command provided by the user as a base64-encoded payload. The exploit must be compiled and run locally on the target system. No network endpoints are hardcoded, but the payload can be used to download further code or connect to a C2 server, depending on the attacker's supplied PowerShell command. The code is operational and requires the attacker to supply their own payload.
This repository contains proof-of-concept (PoC) exploit code for CVE-2024-26229, a local privilege escalation vulnerability in the Microsoft Windows csc.sys driver, affecting Windows 11 22H2 Build 22621. The repository provides two implementations: one for Cobalt Strike (in the 'Cobalt Strike' directory) and one for BruteRatel (in the 'BruteRatel' directory), both as Beacon Object Files (BOFs) suitable for use with their respective post-exploitation frameworks. The main exploit logic is implemented in 'CVE-2024-26229-bof.c' in each directory, with supporting headers for framework integration. The exploit works by leaking kernel addresses of process and thread objects, then using a vulnerable IOCTL in csc.sys to perform a Direct Kernel Object Manipulation (DKOM) attack, overwriting the current process's token with the SYSTEM token, thus achieving SYSTEM privileges. The exploit is a PoC and does not include weaponized or highly automated payloads. The only fingerprintable endpoint is the device object name '\Device\Mup\;Csc\.\.' and the csc.sys driver. The repository is well-structured, with clear separation for each framework, and includes a README with compilation instructions and references.
This repository is a Havoc C2 Firebeam plugin that exploits CVE-2024-26229, a local privilege escalation vulnerability in the Windows csc.sys driver. The exploit is implemented as a RISC-V shellcode payload (compiled from C++ sources in src/main.cc and related headers) that is executed via the Firebeam VM. The exploit works by opening a handle to the csc.sys device (\Device\Mup\;Csc\.\.), leaking kernel object addresses, corrupting the KTHREAD->PreviousMode field to gain kernel memory access, and then using Direct Kernel Object Manipulation (DKOM) to copy the SYSTEM process token to the current process, thereby elevating privileges to SYSTEM. The plugin.py script integrates this payload into the Havoc C2 framework, allowing an operator to trigger the exploit from a low-privileged context. The repository includes build scripts, supporting Python scripts for ELF manipulation, and all necessary C++ headers and sources. The exploit is operational and provides SYSTEM-level access if successful.
This repository contains a local privilege escalation (LPE) exploit for CVE-2024-26229, targeting Microsoft Windows systems prior to the April 9, 2024 patch. The exploit is implemented in C (exploit.c) and is a standalone proof-of-concept that does not require additional dependencies. The code interacts directly with Windows kernel structures and leverages a DeviceIoControl vulnerability via the path '\Device\Mup\;Csc\.\.' to perform Direct Kernel Object Manipulation (DKOM). The exploit locates the current process and thread objects, then overwrites the current process's token with that of the SYSTEM process, effectively granting SYSTEM privileges. Upon success, it spawns a SYSTEM-level command prompt (cmd.exe). The repository structure is simple, consisting of a README.md describing the exploit and the main exploit code in exploit.c. No network or remote attack vectors are present; the exploit must be run locally on a vulnerable system.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An improper address validation vulnerability in the Windows csc.sys driver involving an IOCTL with METHOD_NEITHER, described as enabling privilege elevation to kernel on Windows 10.
A local privilege escalation vulnerability in Microsoft Windows, allowing attackers to gain elevated privileges on a compromised system.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.