Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-6769 — Technical writeup and PoC for CVE-2024-6769, chaining DLL hijacking with activation cache poisoning to escalate from medium to high integrity on Windows systems. | Kitploit
Tools/GitHubGitHub/fortra/cve-2024-6769
Privilege EscalationVulnerability AnalysisExploitationPapers & ResearchLearning & EducationBinary Exploitation
GitHubfortra/cve-2024-6769

CVE-2024-6769

Technical writeup and PoC for CVE-2024-6769, chaining DLL hijacking with activation cache poisoning to escalate from medium to high integrity on Windows systems.

View Repository
781182 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Blogpost: CVE-2024-6769 Poisoning the activation cache to elevate from medium to high integrity

This blog is about two chained bugs: Stage one is a DLL Hijacking bug caused by the remapping of ROOT drive and stage two is an Activation Cache Poisoning bug managed by the CSRSS server.

The first stage was presented in detail at Ekoparty 2023 in the presentation called "I'm High" by Nicolás Economou from BlueFrost Security. He explained how to exploit the vulnerability which, at the time, had not yet been patched by Microsoft. This allowed a MEDIUM INTEGRITY user to be elevated to have limited HIGH PRIVILEGES, but without the complete access to be a full Administrator.

The second stage was not presented at that conference, though some steps were suggested to start researching it.

To begin, we will review the first stage to provide introductory context. From there, we’ll dive into my research on the second stage, going into the details of achieving full escalation from limited HIGH INTEGRITY to full Administrator. This includes a complete working PoC for both stages for all Windows versions, which has been successfully tested in Windows 10, Windows 11, Windows Server 2022, and Windows Server 2019 with all updates applied.

Index:

  • Review of the first stage
  • Steps to follow to exploit the second stage.
  • What is the Activation Cache?
  • Using ALPC Attack Vector to Poison the Activation Cache
  • How will the system accept our Activation Context?
  • How to poison the Activation Cache?
  • How is my embedded XML Manifest read?
  • How is the embedded XML manifest parsed?
  • How did my fake imm32.dll ends up loaded?
  • Video Demo.
  • Functional Proof of Concept
  • TL;DR Brief description of exploitation steps

Review of the first stage

A red square with white text and a number on it Description
automatically generated

The only requirement for this stage is that the initial process begins at a MEDIUM INTEGRITY LEVEL and the user belongs to the Administrator group.

The first stage of exploitation can be summarized in the following steps:

  1. Remapping of ROOT Drive using the NtCreateSymbolicLinkObject function.

For example: remapping disk from

"C:\" to "C:\users\public"

This also will remap the "system32" folder from

"C:\windows\system32" to "C:\users\public\windows\system32"

  1. After remapping, some Services are affected and will attempt to load libraries from the new, fake user-controlled system32.

One of these affected programs is CTFMON, which runs at a HIGH INTEGRITY LEVEL but without Administrator privileges.

Normally, it tries to load the module called MsCtfMonitor.dll from the real system32 folder, but since the ROOT drive was remapped, it looks for MsCtfMonitor.dll in our fake controlled system32, where we can create and place a crafted DLL with the same name.

  1. Create MsCtfMonitor.dll

At this point, by placing our version of MsCtfMonitor.dll in the fake system32 folder, its DoMsCtfMonitor function is called and executes our code at a HIGH INTEGRITY LEVEL.

  1. Place a MessageBoxA on the DoMsCtfMonitor function. When MsCtfMonitor.dll is loaded, it will display the MessageBoxA "TRIGGER".

  1. Verify that the DLL was loaded into the CTFMON process that runs at the HIGH INTEGRITY LEVEL:

At the same time, we can corroborate that the process, despite being at a HIGH INTEGRITY LEVEL, does not have Administrator privileges:

Steps for Exploitation of the Second Stage A red square with white text and a number on it Description automatically generated

In his Ekoparty presentation, Nicolas suggested the following steps to complete the exploitation:

While this seems simple, it requires a lot of time to reversing and debugging.

Upon digging a little into this attack vector story, it became clear that the poisoning of the Activation Context Cache has been used in some exploits. Consequently, it is worthwhile to learn how the exploitation has been done previously to provide additional context and insights. Details on this exploitation are available through the Zero Day Initiative’s writeup, Activation Context Cache Poisoning: Exploiting CSRSS for Privilege Escalation.

What is the Activation Cache?

The usage of the Activation cache happens when a program is going to load a library requiring a specific version.

For example, if an application is going to load C:\Windows\System32\comctl32.dll, there is no guarantee that the comctl32.dll in that location is the version that the application needs. This is a basic use case of the Activation Contexts Cache. The program can send a request to the CSRSS server to process a new Activation Context Entry to be entered into the cache, so this program can load the specific library version needed.

For this purpose, the so-called manifest is used, which is in XML format. It is usually embedded as a resource in an EXE or DLL file. Alternatively, Windows will search for a manifest file in the same folder where the program's executable is located.

The URL mentioned above has some examples of Manifest files used by old exploits, such as tricking the system to load the library advapi32.dll from a controlled directory by the attacker that was reached through PATH TRAVERSAL technique.

Of course, some used attack vectors were patched, and some new techniques were discovered. Additionally, in the October 2022 patch for Windows 11 22H2, a new check was added.

After this patch was implemented, the check when an Activation Context (ACTX) is registered can only be bypassed if the process which adds the new entry in the cache has the same or higher RID than the process which will use it.

In winnt.h we can see the RID values:

The proposal for bypassing this check is to create a request with an Activation Context from the CTFMON process where the crafted DLL runs. This crafted DLL has RID=0x3000 and after the entry is added to the cache, TCMSETUP with RID=0x3000 will load tapi32.dll.

Download Tool