Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ps-ppl-bypass — Process Explorer vulnerable driver PPL Bypass | Kitploit
Tools/GitHubGitHub/r41n3rzuf477/ps-ppl-bypass
Defensive ToolsPrivilege EscalationVulnerability AnalysisExploitationPost-ExploitationRed TeamingPayload DevelopmentBinary Exploitation
GitHubr41n3rzuf477/ps-ppl-bypass

ps-ppl-bypass

Process Explorer vulnerable driver PPL Bypass

View Repository
11341 day agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Process Explorer vulnerable driver PPL Bypass

While it is well known that old versions (before 17.x) of SysInternals Process Explorer drivers (PSEXP152.sys) are vulnerable and can be abused to open full access process handles to PPL processes (IOCTL: 0x8335003c), newer versions (17.x upward) are still vulnerable and capable of doing the same with a different driver function (IOCTL: 0x83350014). This IOCTL function duplicates arbitrary handles and also got a patch to filter the system process and any protected process (PP/PPL) in driver version 17.00. But there was a major oversight with this function, as it was still possible to duplicate any process and thread handle from your own non-PPL process. Just opening a PPL process with low permissions like PROCESS_QUERY_LIMITED_INFORMATION and then duplicating this handle from your own process via Process Explorer driver was enough to bypass the filter and receiving a full access handle to a PPL process. I used this method years ago to bypass PPL process protection, but Microsoft patched this bypass with driver version 17.11 by checking now if the target handle is a PPL process or thread handle. Still, driver versions from 17.00 up to 17.09 (17.10 does not exist) are not included in Microsoft's vulnerable driver blocklist and I suspect some EDR vendors also don't flag these versions (for now).

This is just PoC implementation to kill PPL processes. The same powerful handle duplication IOCTL can also be used to duplicate other handle types like threads and to inject shellcode in other PPL processes.

Usage:
1. Download older SysInternals Process Explorer (17.00 to 17.10)
2. Run procexp64.exe as administrator to load the vulnerable driver
3. Look in Process Explorer for the PID of for example MsMpEng.exe (ex: 3660)
4. Run ps_ppl_bypass.exe PID ("ps_ppl_bypass.exe 3660") as administrator to kill the target process

It is also still possible to get an old driver version from offical SysInternals website by extracting it from SysInternals Handles tool: https://learn.microsoft.com/en-us/sysinternals/downloads/handle

Download Tool