Skip to content
SheldonCybersecurity researcher & developer
  • Profile
  • Work
  • Blogs
  • Pentest Book
  • Contact

Research topics

All articlesreverse engineering 8security research 7kernel exploitation 6windows internals 6privilege escalation 5malware analysis 3kernel pool 3data only attacks 3
All topics
reverse engineering 8security research 7kernel exploitation 6windows internals 6privilege escalation 5malware analysis 3kernel pool 3data only attacks 3race condition 2use after free 2byovd 2ioctl 2ot security 1ics 1air gap 1stuxnet 1triton 1wirelesshart 1cve 2025 62215 1double free 1object manager 1token 1clickfix 1infostealer 1acr stealer 1macos stealer 1windows 1blockchain 1c2 1cve 2026 21241 1afd sys 1pool spray 1kcfg 1cve 2024 30088 1toctou 1virtual memory 1ntoskrnl 1physical memory 1throttlestop 1cve 2025 7771 1race conditions 1syscall hooking 1patchguard 1virtualization based security 1kaslr 1smep 1smap 1code integrity 1cet 1secure boot 1kernel 1dynamic analysis 1ssdt 1rootkit 1
Back to profile

Research / Topic archive

afd sys.

Research, walkthroughs, and field notes on afd sys.

1 article

Allreverse engineeringkernel exploitationwindows internalsmalware analysisafd sys

kernel exploitation

Exploiting CVE-2026-21241: A Use-After-Free Race in AFD.sys

A deep-dive into CVE-2026-21241 — a use-after-free race in afd.sys's socket notification path, where a notification object is freed across a spinlock release, reclaimed with a named-pipe spray, and pivoted through kCFG-legal RtlSetBit calls into a KDP-evading SeDebugPrivilege flip and SYSTEM.

Sep 8, 2026 · 33 min read

© 2026 Noman Nasir Minhas / Sheldon