CVE-2024-35250 is a Windows local privilege escalation vulnerability in a kernel-mode driver, identified as affecting ks.sys. Available reporting indicates exploitation can yield arbitrary kernel memory read and write by abusing RtlClearAllBits within the driver. As a kernel-mode flaw, successful exploitation enables transition from user mode into a highly privileged kernel context. Public references also indicate the vulnerability has been used as a kernel read/write primitive and has been discussed in the context of bypassing protections in HVCI-enabled environments.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository implements a local Windows privilege escalation exploit for CVE-2024-35250 (ks.sys Kernel Streaming). It is a Visual Studio C project (solution + vcxproj) with a small set of C modules that: (1) enumerates and opens a KS audio/render device interface using SetupAPI (device.c), (2) leaks kernel addresses using NtQuerySystemInformation (leak.c) to obtain the kernel base and the current process EPROCESS pointer, (3) triggers the vulnerable IOCTL_KS_PROPERTY with KSPROPERTY_TYPE_TOPOLOGY and attacker-controlled NodeId to achieve an out-of-bounds read/write primitive (krw.c). The exploit performs pool feng shui by spraying thousands of named pipes (\\.\\pipe\\krw_<n>) and then scanning OOB reads for a kernel pointer aligned like a kernel object address; this is used to calibrate a relative read/write primitive. (4) With kernel R/W, it walks the ActiveProcessLinks list from the current EPROCESS to find PID 4 (System) and overwrites the current process token with the System token (token.c), then spawns an elevated shell via CreateProcessW("C:\\Windows\\System32\\cmd.exe"). Key entry points: main.c calls exploit_run() (exploit.c), which resolves build-specific EPROCESS offsets (resolve_offsets in token.c), opens the KS device, initializes the kernel R/W primitive (krw_init), performs token theft (token_elevate), and spawns a SYSTEM cmd.exe. No network C2 or remote endpoints are present; all interaction is local via device IOCTLs and named pipes. The exploit is ‘data-only’ (no kernel shellcode), explicitly aiming to bypass HVCI/KMCI by only modifying kernel data structures.
This repository contains a functional local privilege escalation exploit for CVE-2024-35250, targeting the ks.sys driver on specific Windows 10 and 11 builds. The main exploit logic is implemented in 'CVE-2024-35250.cpp', which leverages an untrusted pointer dereference vulnerability (CWE-822) in the kernel streaming driver. The exploit works by crafting fake kernel objects and using DeviceIoControl to trigger the vulnerability, ultimately allowing the attacker to overwrite sensitive kernel fields (such as EPROCESS->Token) and spawn a SYSTEM-level shell. The exploit is operational and requires medium integrity privileges on a vulnerable system running under VMWare Workstation (not Hyper-V). The 'common.h' file provides kernel structure offsets and helper definitions for cross-version compatibility. The only fingerprintable endpoint is the device path for the vulnerable driver. The repository is a standalone PoC and does not use any exploit framework.
This repository contains a proof-of-concept (PoC) local privilege escalation exploit for CVE-2024-35250, targeting Microsoft Windows versions 10.0.10240 through 10.0.25398. The main exploit logic resides in 'GiveMeKernel.cpp', which leverages Windows kernel APIs and device IOCTLs to manipulate kernel memory structures, specifically process tokens, to elevate privileges to SYSTEM. The exploit interacts with kernel device objects (notably a DRM device) and the Windows kernel module (ntoskrnl.exe) to perform its actions. Upon successful exploitation, it spawns a SYSTEM-level command prompt (cmd.exe). The code is condensed and optimized for clarity and efficiency, as described in the README. The repository includes two code files ('GiveMeKernel.cpp' and 'Helpers.h') and a README.md with usage notes and prerequisites. The attack vector is local, requiring execution on a vulnerable Windows system. Notable fingerprintable endpoints include the DRM device object path and references to 'ntoskrnl.exe' and 'winlogon.exe'.
This repository contains a single Metasploit module (Ruby file) that exploits CVE-2024-35250, a local privilege escalation vulnerability in the ks.sys driver on Windows. The exploit targets 64-bit versions of Windows 10 (1607-22H2), Windows 11 (21H2, 22H2), and Windows Server (2016-2022) where the vulnerable ks.sys driver is present. The module checks for the presence of the driver and the correct Windows version, then launches notepad.exe as a host process and injects a custom DLL containing the attacker's payload (default: Meterpreter reverse shell). If successful, the attacker gains SYSTEM privileges. The module is weaponized, allowing for customizable payloads and reliable exploitation within the Metasploit framework. Key fingerprintable endpoints include the ks.sys driver file, the notepad.exe process used for injection, and the exploit DLL. The repository is structured as a single Ruby file compatible with Metasploit's exploit module system.
This repository implements a proof-of-concept (PoC) exploit for CVE-2024-35250 as a Beacon Object File (BOF) for Cobalt Strike. The main exploit logic resides in 'CVE-2024-35250-BOF/CVE-2024-35250-BOF.cpp', which targets a local privilege escalation vulnerability (CWE-822: Untrusted Pointer Dereference) in specific Windows 10 and 11 builds. The exploit allocates a fake bitmap structure in memory, manipulates kernel objects, and ultimately spawns a shell as NT AUTHORITY\SYSTEM. The code is designed for use in a VMWare Workstation environment and does not work in Hyper-V. The repository includes supporting headers and mock/test infrastructure for development and unit testing. Notable fingerprintable endpoints include a specific device object path used for kernel interaction and references to the system directory. The exploit is not weaponized for mass deployment but provides a working PoC for researchers and red teamers.
This repository provides a Beacon Object File (BOF) implementation of an exploit for CVE-2024-35250, a local privilege escalation vulnerability affecting specific versions of Microsoft Windows (Windows 10 20H2 Build 19042 and Windows 11 22H2 Build 22621). The exploit is written in C/C++ and is designed to be compiled with Visual Studio. It leverages a kernel vulnerability (CWE-822: Untrusted Pointer Dereference) in a DRM device driver, accessed via a specific device path, to perform arbitrary kernel memory read/write operations. The exploit manipulates kernel structures such as EPROCESS->Token and KTHREAD->PreviousMode to escalate privileges from a medium integrity process to SYSTEM. Upon success, it spawns a SYSTEM-level shell (cmd.exe). The code is intended for use as a post-exploitation tool within Cobalt Strike via its BOF interface. The repository also includes a PowerShell script to strip debug symbols from the compiled object file. The exploit is not operational in Hyper-V environments and is specifically tested on VMWare Workstation. The README provides basic usage information and credits the original vulnerability author.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unknown (referenced as a Windows local exploit module name in Metasploit; no vulnerability details are provided in the content).
A high-severity Windows kernel vulnerability (CVE-2024-35250) that is currently being targeted in ongoing attacks, prompting CISA to issue warnings to U.S. federal agencies.
A local privilege escalation vulnerability in Microsoft Windows, allowing attackers to gain elevated privileges on a compromised system.
An elevation of privilege vulnerability in a Windows kernel-mode driver.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.