Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-22077 — BYOVD exploitation framework for CVE-2022-22077 targeting RTCore64.sys. Demonstrates kernel token theft, privilege escalation to SYSTEM, and C2 beacon integration for red team operations and security research. | Kitploit
Tools/GitHubGitHub/grisuno/cve-2022-22077
Privilege EscalationExploitationPost-ExploitationCommand and ControlLearning & EducationRed TeamingPayload DevelopmentBinary Exploitation
GitHubgrisuno/cve-2022-22077

CVE-2022-22077

BYOVD exploitation framework for CVE-2022-22077 targeting RTCore64.sys. Demonstrates kernel token theft, privilege escalation to SYSTEM, and C2 beacon integration for red team operations and security research.

551111 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
Website

✅ CVE-2022-22077 exploitation framework RTCore64.sys:

image

This document provides a comprehensive overview of the CVE-2022-22077 exploitation framework, a sophisticated BYOVD (Bring Your Own Vulnerable Driver) attack toolkit that targets the RTCore64.sys driver vulnerability. This framework demonstrates advanced Windows kernel exploitation techniques for educational and security research purposes.

The material covered includes the vulnerability's technical foundation, the framework's architecture, and the integration with the broader LazyOwn RedTeam toolkit. For detailed vulnerability analysis, see Vulnerability Analysis. For specific implementation details of individual components, see Exploitation Framework.

image

🚨 CVE-2022-22077 — MSI Center / Dragon Center — Arbitrary Memory Read/Write via RTCore64.sys

CVE-2022-22077 is a high-severity vulnerability (CVSS score 7.8) affecting the RTCore64.sys driver distributed with MSI Center and Dragon Center applications. The vulnerability stems from exposed IOCTL interfaces that allow unprivileged users to perform arbitrary physical memory reads and writes, effectively bypassing all Windows kernel security mechanisms.

image

Key Impact Areas:

  • Local privilege escalation to SYSTEM
  • EDR/AV bypass capabilities
  • Kernel-mode code execution
  • Rootkit installation potential
image

Stages

image

Stage 1: Environment Preparation

  • File: install.sh - Sets up mingw-w64 cross-compilation environment
  • File: build.sh - Compiles Windows executables from Linux host
  • Integration: LazyOwn framework configuration via CVE-2022-22077.yaml

Stage 2: Automated Deployment

  • File: payload.ps1 - PowerShell script handling:
  • Privilege validation (SeLoadDriverPrivilege)
  • VBS/HVCI compatibility checks
  • Driver and exploit download from remote server
  • Windows service creation and management

Stage 3: Kernel Exploitation

  • File: exploit.c - Native code implementing:
  • RTCore64.sys device communication
  • SYSTEM process token extraction
  • Current process token replacement
  • Privilege escalation validation
image

Memory Manipulation Architecture

The framework implements kernel memory access through a structured approach using the RTCore64.sys driver vulnerabilities:

image

Article

descarga 2

The RTCore64 Chronicles: When Your GPU Tuner Becomes a Kernel Assassin (And Why That’s a Feature, Not a Bug)

By: grisun0, Chief Architect of Kernel Chaos & Part-Time Driver Whisperer - LazyOwn RedTeam

7 min read · Published at 3:33 AM because “HVCI? Never met her.”

“The best way to own a system is to ask its own driver for permission — politely, with IOCTLs.” — grisun0, probably while reverse-engineering MSI Afterburner in his underwear

Let’s skip the part where I pretend this is normal.

If you’re reading this, you’re either:

  • A red teamer who just turned RTCore64.sys into a kernel backdoor while sipping matcha,
  • A blue teamer staring at \.\RTCore64 in ProcMon thinking, “Why does my GPU need to read PsInitialSystemProcess?”,
  • Or someone who Googled “how to become SYSTEM with a gaming driver” and ended up here. (Spoiler: It’s not only possible — it’s elegant.)

Welcome to LazyOwn RedTeam™, where we don’t bypass security — we invite it to dinner and then steal its wallet.

Today, I introduce you to RTCore64.sys — not a driver, not a tool, but a fully operational kernel exploit disguised as a utility for overclocking your RTX 3090.

And yes — there’s a twist.

Spoiler: It still uses cmd.exe. Bigger spoiler: Now it uses beacon.exe too. Even bigger spoiler: Both are now running with NT AUTHORITY\SYSTEM privileges, thanks to a driver that thought “arbitrary kernel memory access” was a quality-of-life feature.

🕳️ What Is RTCore64.sys? (Or: “How to Turn MSI Afterburner Into a Ring 0 Backdoor”) Imagine installing a driver to tweak your GPU voltage… and accidentally giving yourself full read/write access to kernel memory.

This is CVE-2022–22077 — a vulnerability so beautifully reckless, it makes capcom.sys look like a shy librarian.

While capcom.sys asked nicely to execute your callback, RTCore64.sys just hands you the keys to the kingdom — no questions asked.

“Here’s an IOCTL. Write any address. Read any value. Go nuts.” — MSI, probably

And because we’re professionals, we don’t just DeviceIoControl randomly. We steal SYSTEM tokens, patch EPROCESS structures, and spawn SYSTEM shells — all before your GPU hits 70°C.

🔧 How RTCore64.sys Works: A Symphony of IOCTLs and Impunity

Let me walk you through the five acts of this digital heist:

  1. The Setup: “I’m Just a Gamer, Officer” You download MSI Afterburner to overclock your GPU. Harmless, right?

Wrong.

Buried inside is RTCore64.sys — a signed, vulnerable driver that exposes IOCTLs like:

0x80002048 → Read kernel memory 0x8000204c → Write kernel memory No validation. No sanity checks. Just raw, unfiltered power.

“Why sandbox when you can kernel?” — MSI Engineering Team, 2019

  1. The Load: “BYOVD? More Like Bring Your Own Gaming Rig” You don’t even need to install MSI Afterburner.

Just:

sc create RTCore64 binPath=C:\Windows\Temp\RTCore64.sys type=kernel

sc start RTCore64

Boom. Kernel access unlocked.

Prerequisite: SeLoadDriverPrivilege (which you already have, because you’re that good). Bonus: HVCI disabled (because who needs virtualization when you have style?).

  1. The Exploit: “Token Stealing for Dummies (And Geniuses)” Here’s the sequence:

CreateFileW(L"\\.\RTCore64", ...) → Grab the golden ticket. EnumDeviceDrivers() → Find ntoskrnl.exe base. Parse PsInitialSystemProcess from disk → Get offset. Read EPROCESS of SYSTEM → Steal its token. Write token into your own process → Congratulations, you’re God. CreateProcessW(L"beacon.exe", ...) → Spawn your payload as SYSTEM. No shellcode. No ROP chains. Just pure, unadulterated kernel object manipulation.

  1. The Cover-Up: “Logs? What Logs?” wevtutil cl security

del C:\Windows\Temp\RTCore64.sys

sc delete RTCore64

Poof. Gone. Like a ghost who overclocked your RAM and vanished.

  1. The Flex: “I Dumped LSASS With a Gaming Driver” Once you’re SYSTEM:

tasklist /m mimilib.dll

eventcreate /t INFORMATION /id 1 /l APPLICATION /d “sekurlsa::logonpasswords”

type C:\Windows\System32\mimilsa.log

→ Domain Admin hashes? Check. → Plaintext passwords? Check. → Golden Tickets? Coming right up.

Download Tool