Security researchers are increasingly turning their attention to privilege escalation attacks that exploit two key attack surfaces in Windows: kernel drivers and named pipes.
See also: CyberVolk's new VolkLocker ransomware targets Linux and Windows

These attacks exploit weaknesses in the trust boundaries between user mode and kernel mode, allowing an attacker to elevate their privileges from a simple user to SYSTEM. Kernel drivers are a particularly vulnerable LPE surface, mainly due to insufficient control of incoming data when processing IOCTL requests.
In WDM-based drivers and the METHOD_BUFFERED, the I/O Manager allocates memory to the kernel, but does not adequately check the data provided by the user before it is processed by the kernel. This loophole allows the creation of malicious IOCTL requests with manipulated pointer and length values, which the kernel interprets as valid memory addresses.
This allows the attacker to call dangerous kernel functions, such as MmMapIoSpace, gaining arbitrary memory read and write capabilities. These capabilities enable token theft attacks, where the SYSTEM process token is copied into the EPROCESS structure of the current process, ultimately leading to privilege escalation.
See also: Windows RasMan vulnerability allows arbitrary code execution

Named pipes, which are widely used for inter-process communication by highly privileged SYSTEM services, are an equally dangerous attack vector.
Unlike kernel drivers, named pipes rely on message-passing protocols rather than direct memory access. However, many service applications implicitly trust them. The attack methodology involves identifying named pipes owned by SYSTEM and having overly lax access control lists (ACLs), allowing read and write permissions to any user, and reverse engineering the communication protocol through static analysis.
Research has uncovered instances where services process requests without adequate authorization checks. For this reason, security teams should thoroughly check third-party kernel drivers for excessive IOCTL privileges and ensure that all user data is verified before being processed by the kernel.
See also: Microsoft finally has a prettier Run dialog for Windows 11

At the same time, named pipes implementations should implement explicit permission checks on sensitive operations and strict validation of the communication protocol. According to research published by the Hackyboiz, organizations should list all exposed named pipes and disable those with overly permissive ACLs.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
