
Report and exploit of CVE-2024-21305.
This repo contains the report and PoC of CVE-2024-21305, the non-secure Hypervisor-Protected Code Integrity (HVCI) configuration vulnerability. This vulnerability allowed arbitrary kernel-mode code execution, effectively bypassing HVCI, within the root partition. For the root cause, read the blog post coauthored with Andrea Allievi (@aall86), a Windows Core OS engineer who analyzed and fixed the issue.
The report in this repo is what I sent to MSRC, which contains the PoC and an initial analysis of the issue.
Thanks MSRC for transparent communication and the engineering team, specifically Andrea, for fixing this issue.