kernel exploitation
Exploiting CVE-2025-62215: A Reference-Count Race in the Object Manager
A deep-dive into CVE-2025-62215 — an actively exploited race in ntoskrnl's Object Manager that double-frees the token's SID Values Block, reclaimed with a same-bucket spray and pivoted into a data-only token flip for SYSTEM.
· 30 min readkernel exploitation
Exploiting CVE-2024-30088: A TOCTOU Race in the Windows Kernel
A deep-dive into CVE-2024-30088 — a TOCTOU race in ntoskrnl's AuthzBasepCopyoutInternalSecurityAttributes, exploited by flipping a user-memory pointer to redirect the kernel's own copy into kernel space, then pivoting the fixed-value write through an I/O Ring into SYSTEM.
· 24 min read