Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
PPLwindow — Proof-of-concept PPL bypass abusing the NtUserGetWindowProcessHandle syscall to obtain a handle to protected Windows processes without admin privileges. | Kitploit
Tools/GitHubGitHub/r41n3rzuf477/pplwindow
Privilege EscalationVulnerability AnalysisExploitationPost-ExploitationPenetration TestingRed TeamingBinary Exploitation
GitHubr41n3rzuf477/pplwindow

PPLwindow

Proof-of-concept PPL bypass abusing the NtUserGetWindowProcessHandle syscall to obtain a handle to protected Windows processes without admin privileges.

View Repository
54449 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

PPLwindow

PPLwindow is a Proof-of-Concept for a PPL Bypass that affects Windows 10 1809 to Windows 11 23H2. The NtUserGetWindowProcessHandle syscall from win32kfull.sys driver doesn't properly check if a process is a protected process on the mentioned Windows versions. This can be abused to get a process handle with PROCESS_QUERY_LIMITED_INFORMATION | PROCESS_VM_OPERATION | PROCESS_VM_READ | PROCESS_VM_WRITE | PROCESS_DUP_HANDLE to a protected process from an unprotected process.

The target protected process needs a window for this bypass to work. The PoC exploits WerFaultSecure.exe and achieves PP-WinTcb. For this bypass no admin privileges are required. It was fixed in Windows 11 24H2.

I saw this post from James Forshaw: https://infosec.exchange/@tiraniddo/115539156769921108 My first reaction was: Wait a seconds. I know this. I already found this in 2023 together with CVE-2023-41772, but couldn't find a protected process as a valid target. So thanks to James Forshaw for finding a good target (WerFaultSecure.exe). I told Microsoft about this, when I reported CVE-2023-41772. This might be the reason why this was fixed in Windows 11 24H2.

For Windows 10 1809 / Windows Server 2019 you can use the WerFaultSecure.exe and wer.dll binaries from Windows 10 21H2 / Windows Server 2022. Put both binaries in a folder and provide the path to WerFaultSecure.exe as first command line argument to PPLwindow.

PPLwindow PPL Bypass

Download Tool