HomeSecurityPrivilege escalation in Windows via LPE vulnerabilities

Privilege escalation in Windows via LPE vulnerabilities

Security researchers are increasingly turning their attention to privilege escalation attacks that exploit two key attack surfaces in Windows: kernel drivers and named pipes.

See also: CyberVolk's new VolkLocker ransomware targets Linux and Windows

Windows LPE

These attacks exploit weaknesses in the trust boundaries between user mode and kernel mode, allowing an attacker to elevate their privileges from a simple user to SYSTEM. Kernel drivers are a particularly vulnerable LPE surface, mainly due to insufficient control of incoming data when processing IOCTL requests.

In WDM-based drivers and the METHOD_BUFFERED, the I/O Manager allocates memory to the kernel, but does not adequately check the data provided by the user before it is processed by the kernel. This loophole allows the creation of malicious IOCTL requests with manipulated pointer and length values, which the kernel interprets as valid memory addresses.

This allows the attacker to call dangerous kernel functions, such as MmMapIoSpace, gaining arbitrary memory read and write capabilities. These capabilities enable token theft attacks, where the SYSTEM process token is copied into the EPROCESS structure of the current process, ultimately leading to privilege escalation.

See also: Windows RasMan vulnerability allows arbitrary code execution

Privilege escalation in Windows via LPE vulnerabilities

Named pipes, which are widely used for inter-process communication by highly privileged SYSTEM services, are an equally dangerous attack vector.

Unlike kernel drivers, named pipes rely on message-passing protocols rather than direct memory access. However, many service applications implicitly trust them. The attack methodology involves identifying named pipes owned by SYSTEM and having overly lax access control lists (ACLs), allowing read and write permissions to any user, and reverse engineering the communication protocol through static analysis.

Research has uncovered instances where services process requests without adequate authorization checks. For this reason, security teams should thoroughly check third-party kernel drivers for excessive IOCTL privileges and ensure that all user data is verified before being processed by the kernel.

See also: Microsoft finally has a prettier Run dialog for Windows 11

Privilege escalation in Windows via LPE vulnerabilities

At the same time, named pipes implementations should implement explicit permission checks on sensitive operations and strict validation of the communication protocol. According to research published by the Hackyboiz, organizations should list all exposed named pipes and disable those with overly permissive ACLs.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS