CVE-2026-62737 is a local elevation-of-privilege vulnerability in the Windows Kernel affecting recent Windows 11 builds, including reported testing on 24H2 and 25H2. The flaw is described as an untrusted pointer dereference and, more specifically, an authorization and trust-model failure that allows a low-privileged local user to reach a protected kernel execution path indirectly through an NDIS KLoader proxy to ExecutionContext functionality. Through exposed IOCTL handling, attacker-controlled values can be placed into a kernel task structure such that a worker thread later treats one value as a callback pointer and the other as its argument. The vulnerable logic reportedly validates only that the callback lies in kernel address space by comparing it against MmSystemRangeStart before invoking it as Callback(Argument). This gives an attacker control over an indirect kernel call target and its first argument. Public reporting indicates that a proof of concept has been published demonstrating system crash, while full privilege escalation requires pairing the primitive with a separate kernel address disclosure to bypass KASLR.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a compact local Windows kernel exploit PoC for CVE-2026-62737, consisting of a README and a single PowerShell entry-point script. The README documents intended behavior, tested environments, and usage: a non-destructive probe mode and a full trigger mode that crashes the machine. The exploit is not part of a known framework. The main file, ecpoc-route-b.ps1, is a self-contained PowerShell script that embeds C# via Add-Type. The C# code wraps Win32 APIs from kernel32.dll to interact with a device object using overlapped I/O and IOCTLs. Notable constants include IOCTL_INITIALIZE (0x22EC40), IOCTL_QUEUE_TASK (0x22AC54), and IOCTL_REGISTER_USER_THREAD_MONITOR (0x226C5C). The script opens the device path \\.\kloader\{9C0B898D-6275-48EC-81B4-E5EDBE44B535}, prepares unmanaged buffers, creates synchronization events and a worker thread, registers a user-thread monitor, and queues a task intended to exercise the vulnerable ExecutionContext.sys path. The exploit’s core capability is demonstrating an arbitrary kernel-call primitive by supplying a controlled TaskFn marker address and argument marker, then waiting for the kernel worker path to invoke that pointer. The expected outcome is a bugcheck, proving kernel control-flow reached attacker-controlled data. The README explicitly states this is a kernel DoS / primitive demonstration only, not a full local privilege escalation implementation. Operationally, this is a local attack vector only: no network communication, remote C2, or external URLs are present. Fingerprintable observables are primarily the device interface path and the imported system DLL. Overall maturity is OPERATIONAL rather than mere POC because the repository contains working trigger code and a reproducible crash path, but it does not provide a customizable post-exploitation payload or full weaponized LPE chain.
This repository is a standalone Windows local privilege escalation exploit for CVE-2026-62737 targeting the Microsoft-signed kernel driver ExecutionContext.sys. It is not part of a common exploit framework. The main exploit is exploit.c, supported by helper utilities for gadget discovery and lab/manual exploitation. Core exploit capability: exploit.c abuses an ACL bypass through the NDIS KLoader proxy path (\\.\kloader\{9C0B898D-6275-48EC-81B4-E5EDBE44B535}) to access the vulnerable ExecutionContext device as a low-privilege user. It then sends IOCTL 0x22AC54 to queue a task containing an attacker-controlled kernel callback pointer and argument. Because the driver only checks that the callback lies in kernel address space, the exploit points the callback at a kernel stack-pivot gadget and uses the argument as a pointer to a crafted pivot/ROP structure in kernel memory. The ROP chain steals the SYSTEM token by overwriting the current process EPROCESS token field, then terminates the worker thread cleanly and spawns cmd.exe as SYSTEM. Exploit workflow in exploit.c: (1) obtain kernel/module base addresses for KASLR bypass using EnumDeviceDrivers and/or NtQuerySystemInformation, (2) identify or use build-specific ROP gadgets, (3) spray a ROP chain into NonPagedPoolNx via named pipe attributes, (4) leak the sprayed kernel address using SystemBigPoolInformation, (5) open and initialize the vulnerable device through KLoader, (6) queue the pivot task and trigger the worker thread, and (7) verify elevation and spawn a SYSTEM shell. The code supports both automatic and manual modes with operator-supplied addresses. Repository structure: exploit.c is the primary operational exploit. gadget_finder.py is an offline helper that parses a PE64 ntoskrnl.exe image and scans executable sections for required ROP gadgets and exports such as PsInitialSystemProcess and PsTerminateSystemThread. modlist.c enumerates kernel module base addresses to assist with KASLR bypass. leak_info.c enumerates handle table information to recover EPROCESS and SYSTEM token object addresses for a target process. kwrite.c is a lab-assisted helper that, when run as admin with SeDebugPrivilege, writes the ROP chain and pivot descriptor directly into kernel memory via NtWriteVirtualMemory against PID 4. README.md provides a detailed vulnerability explanation, exploitation strategy, affected builds, and usage guidance. Overall, this is a real exploit repository rather than a detector. It contains a functioning local kernel LPE PoC with hardcoded/build-specific payload logic and helper tooling, making it operational but not broadly weaponized.
This repository is a lab-assisted local privilege escalation exploit for CVE-2026-62737 targeting Windows 11 25H2 kernel 10.0.26100.8875. It is not a standalone weaponized exploit: the README and code explicitly require a debugger, a QEMU gdb stub, guest-agent access, a shared folder, and per-boot kernel/module base discovery. The core exploit in `exploit.c` opens the KLoader proxy device `\\.\kloader\{9C0B898D-6275-48EC-81B4-E5EDBE44B535}`, issues IOCTL `0x22EC40` to initialize an ExecutionContext object, waits for an external helper signal via `Z:\go_lab.txt`, then issues IOCTL `0x22AC54` to queue a task whose callback points to a kernel ROP pivot gadget at `nt + 0x6A6A40`. A watcher thread also invokes IOCTL `0x226C5C` to trigger/observe the worker path. After the kernel callback executes, the program checks whether its token is SYSTEM and launches `cmd.exe /c whoami` to prove elevation, writing output to `Z:\lab_shell_out.txt`. The exploit capability is a token-stealing kernel ROP chain: `patch_rop.py` connects through gdb to the VM, reads `PsInitialSystemProcess`, walks `ActiveProcessLinks` to find the exploit process EPROCESS by PID, reads the SYSTEM token, and writes a short ROP chain into writable `ExecutionContext.sys` `.data`. That chain uses fixed build-specific gadgets (`pop rcx`, `pop rdx`, `mov [rcx], rdx`, `pop rsp`, `ret`) to overwrite the current process `_EPROCESS.Token` with the SYSTEM token. The script also sets a conditional hardware breakpoint on the pivot gadget so it can capture the original kernel `RSP`/`RBP` at runtime and patch them into the chain, allowing the worker thread to return cleanly to the dispatcher (`ec+0x629F`) instead of crashing. `trace_rop.py` performs the same setup but single-steps the chain for debugging rather than auto-continuing. Repository structure is coherent and purpose-built for a research lab workflow. `exploit.c` is the main exploit. `patch_rop.py` and `trace_rop.py` are debugger-side helpers that make the exploit viable by supplying missing primitives. `modlist.c` is a KASLR oracle helper that prints loaded module bases including `ntoskrnl` and `ExecutionContext.sys`. `refresh_bases.sh` automates updating hardcoded per-boot base addresses in the gdb scripts using `ga.py`, which itself is a helper for executing commands inside the Windows VM through the QEMU guest agent over libvirt (`qemu:///system`, default domain `win11`). Overall, this is a real exploit repository, but its operational scope is limited to a controlled VM lab because the crucial address leak and kernel-memory write are outsourced to debugger tooling rather than achieved by the exploit alone.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows Kernel elevation of privilege vulnerability caused by an untrusted pointer dereference weakness that could allow attackers to gain system privileges.
An elevation-of-privilege vulnerability affecting the Windows kernel that was publicly disclosed prior to patch release, with a proof-of-concept exploit described in a blog post.
A Windows 11 kernel local privilege escalation vulnerability caused by an ACL bypass via the NDIS KLoader proxy and unsafe execution of user-controlled kernel callback pointers in ExecutionContext.sys.
A Windows 11 kernel local privilege escalation vulnerability caused by an ACL/trust-boundary failure in the NDIS KLoader proxy path that lets a low-privileged user reach ExecutionContext and inject attacker-controlled kernel callback and argument values, leading to a controlled indirect kernel call.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.