
Exploit PoC for CVE-2026-40369 targeting Windows kernel; includes kASLR bypass, heap grooming, remote thread injection, and per-build offsets.
poc and exp for CVE_2026_40369, related to my analyze, use cmake.
Debug code, poc and exp files for reproducing CVE_2026_40369, written with cmake. As before, you can compile it directly using the regular cmake commands.

About the analysis article:
Maybe our WeChat Official Account < 不止Sec > has more content you might be interested in

[2026-7-23]: Tried to bypass kASLR with the prefetch tool, but it still has a high probability of causing a blue screen, and in real engagements it basically cannot land.

ntoskrl.exe in advance, which is difficult on 25H2. So my/original exp needs to be set manually.CmpLayerVersions address. Alternatively, you can also use a different version information location to construct the victim fake chunk.include\common\gadget.hpp.CmpLayerVersionCount, although I think it does not matter.