kernel exploitation
Exploiting CVE-2025-62215: A Reference-Count Race in the Object Manager
A deep-dive into CVE-2025-62215 — an actively exploited race in ntoskrnl's Object Manager that double-frees the token's SID Values Block, reclaimed with a same-bucket spray and pivoted into a data-only token flip for SYSTEM.
· 30 min readkernel exploitation
Exploiting CVE-2026-21241: A Use-After-Free Race in AFD.sys
A deep-dive into CVE-2026-21241 — a use-after-free race in afd.sys's socket notification path, where a notification object is freed across a spinlock release, reclaimed with a named-pipe spray, and pivoted through kCFG-legal RtlSetBit calls into a KDP-evading SeDebugPrivilege flip and SYSTEM.
· 33 min read