Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone local privilege escalation proof of concept for CVE-2026-36981 affecting MiniTool's pwdrvio.sys kernel driver. The repository contains three files: an MIT license, a single C exploit source file (LPE_PoC.c), and a large README documenting discovery, debugging, and exploitation context. The exploit is not part of a larger framework. The main exploit logic is in LPE_PoC.c. It opens the device \\.\PartitionWizardDiskAccesser\0 with read/write access, pauses for manual debugger interaction, then issues a WriteFile call with a 0x100-byte buffer to reach the vulnerable IRP_MJ_WRITE path. The code is explicitly debugger-assisted rather than fully automated: it instructs the operator to set a WinDbg breakpoint at driver offset 0x1641 and continue execution. After the vulnerable write path is triggered, the PoC attempts to demonstrate success by running 'whoami && cmd.exe', implying a SYSTEM shell if the kernel write primitive has been leveraged correctly. The README provides the technical rationale: the vulnerable driver allegedly exposes an arbitrary kernel write primitive in pwdrvio.sys at offset 0x1641 ('mov qword ptr [r11-10h],rax'), enabling write-what-where behavior suitable for elevation of privilege. It states prerequisites of local access, a low-privileged user account, and the vulnerable MiniTool driver being loaded. It also documents a kernel debugging environment using VMware serial named pipes and WinDbg, plus the driver path C:\Windows\System32\drivers\pwdrvio.sys and service name pwdrvio. Overall, this is a real exploit PoC for a local Windows kernel driver vulnerability. It is operational but not weaponized: it demonstrates the vulnerable access path and post-exploitation shell launch, but depends on manual debugger assistance and does not contain a fully automated privilege-escalation chain.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.