Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2026-62737 — PowerShell proof-of-concept that triggers CVE-2026-62737, an arbitrary kernel call in ExecutionContext.sys, causing a controlled kernel crash on Windows 11. | Kitploit
工具/GitHubGitHub/loanvui/cve-2026-62737
Vulnerability AnalysisExploitationBinary Exploitation
GitHubloanvui/cve-2026-62737

CVE-2026-62737

PowerShell proof-of-concept that triggers CVE-2026-62737, an arbitrary kernel call in ExecutionContext.sys, causing a controlled kernel crash on Windows 11.

查看仓库
31721天前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
内容在请求的语言中不可用。显示英文版本。

CVE-2026-62737 — ExecutionContext.sys Arbitrary Kernel Call

Proof of concept for CVE-2026-62737: ExecutionContext.sys invokes a user-controlled TaskFn pointer in kernel mode without validation, producing a controlled kernel crash.

Validated on stock Windows 11 25H2 (build 26200.8655, ARM64): 0x7E SYSTEM_THREAD_EXCEPTION_NOT_HANDLED, with the faulting RIP set to the PoC's controlled TaskFn marker.

The same script did not crash an unmodified Windows 11 24H2 system (build 26100.5074, x64) because Windows kept the vulnerable kernel path disabled behind an internal feature flag. In a separate lab-only test, we manually changed that flag in live kernel memory and then observed a 0x50 crash. Because that test modified the running kernel, it is not a stock 24H2 reproduction.

This PoC demonstrates the arbitrary kernel-call primitive and a kernel DoS.

Self-contained PowerShell script using C# Add-Type; supports x64 and ARM64.

下载工具