Skip to content

About

Windows kernel vulnerability research: PoC and analysis notes

Resources

Stars

1 star

Watchers

0 watching

Forks

Latest commit

 

History

169 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 

Repository files navigation

WindowsKernelVulns

Windows kernel vuln research. BinDiff analysis, PoCs, and WinDbg notes for patched CVEs.

Targets are x64 Windows 11 24H2 unless noted otherwise.

Structure

research/
  notes/      - patch diff analysis per CVE
  summaries/  - per-binary progress and pattern summaries
  poc/        - proof of concept code

Binary Summaries

CVEs

CVE Component Bug class Notes
CVE-2026-25179 afd.sys Input validation / bounds enforcement Notes
CVE-2026-25178 afd.sys Input validation / bounds enforcement Notes
CVE-2026-25176 afd.sys Input validation / bounds enforcement Notes
CVE-2026-25175 ntfs.sys Input validation / bounds enforcement Notes
CVE-2026-25174 exfat.sys Input validation / bounds enforcement Notes
CVE-2026-24293 afd.sys Input validation / bounds enforcement Notes
CVE-2026-24290 projectedfslib.dll Input validation / bounds enforcement Notes
CVE-2026-23673 refs.sys Input validation / bounds enforcement, Lifetime / state management Notes
CVE-2026-23672 udfs.sys Lifetime / state management Notes
CVE-2026-21250 http.sys Input validation / bounds enforcement Notes
CVE-2026-21241 afd.sys Input validation / bounds enforcement Notes
CVE-2026-21240 http.sys Input validation / bounds enforcement Notes
CVE-2026-21238 afd.sys Input validation / bounds enforcement Notes
CVE-2026-21236 afd.sys Input validation / bounds enforcement Notes
CVE-2026-20940 cldflt.sys Input validation / bounds enforcement Notes
CVE-2026-20929 http.sys Input validation / bounds enforcement, Lifetime / state management Notes
CVE-2026-20860 afd.sys Input validation / bounds enforcement Notes
CVE-2026-20857 cldflt.sys Input validation / bounds enforcement Notes
CVE-2026-20831 afd.sys Input validation / bounds enforcement Notes
CVE-2026-20820 clfs.sys Patch-delta under active reverse engineering Notes
CVE-2026-20810 afd.sys Input validation / bounds enforcement Notes
CVE-2025-64673 storvsp.sys Input validation / bounds enforcement Notes
CVE-2025-62470 clfs.sys Input validation / bounds enforcement Notes
CVE-2025-62467 projectedfslib.dll Input validation / bounds enforcement, Patch-delta under active reverse engineering Notes
CVE-2025-62464 projectedfslib.dll Input validation / bounds enforcement, Patch-delta under active reverse engineering Notes
CVE-2025-62462 projectedfslib.dll Input validation / bounds enforcement, Patch-delta under active reverse engineering Notes
CVE-2025-62461 projectedfslib.dll Input validation / bounds enforcement, Patch-delta under active reverse engineering Notes
CVE-2025-62457 cldflt.sys Input validation / bounds enforcement, Lifetime / state management Notes
CVE-2025-62454 cldflt.sys Input validation / bounds enforcement, Lifetime / state management Notes
CVE-2025-62221 cldflt.sys Input validation / bounds enforcement, Lifetime / state management Notes
CVE-2025-62217 afd.sys Input validation / bounds enforcement Notes
CVE-2025-62213 afd.sys Input validation / bounds enforcement Notes
CVE-2025-60720 tdx.sys Lifetime / state management Notes
CVE-2025-60719 afd.sys Input validation / bounds enforcement Notes
CVE-2025-60709 clfs.sys Improper bounds validation leading to out-of-bounds record pointer return Notes
CVE-2025-59517 storvsp.sys Improper authorization on privileged vSMB share-root operations Notes
CVE-2025-59516 storvsp.sys authorization bypass Notes
CVE-2025-59242 afd.sys Improper input validation Notes
CVE-2025-58714 afd.sys Improper validation of user-controlled length/offset fields leading to an out-of-bounds in-place buffer rewrite Notes
CVE-2025-55687 refs.sys Insufficient patch evidence to confirm bug class Notes
CVE-2025-55680 cldflt.sys Improper user-buffer capture / TOCTOU-style trust of a live caller-backed mapping Notes
CVE-2025-55339 ndis.sys Improper validation of embedded buffer offsets in nested variable-length descriptors Notes
CVE-2025-55335 ntfs.sys Improper initialization of per-file TxF transaction context Notes
CVE-2025-55233 projectedfslib.dll Integer overflow leading to heap-based buffer overflow Notes
CVE-2025-54099 afd.sys Input validation / bounds enforcement Notes
CVE-2025-53718 afd.sys Input validation / bounds enforcement, Lifetime / state management Notes
CVE-2025-53154 afd.sys Input validation / bounds enforcement, Lifetime / state management Notes
CVE-2025-53147 afd.sys Input validation / bounds enforcement, Lifetime / state management Notes
CVE-2025-53141 afd.sys Input validation / bounds enforcement, Lifetime / state management Notes
CVE-2025-53137 afd.sys Input validation / bounds enforcement, Lifetime / state management Notes
CVE-2025-53134 afd.sys Input validation / bounds enforcement, Lifetime / state management Notes
CVE-2025-50170 cldflt.sys Input validation / bounds enforcement Notes
CVE-2025-49762 afd.sys Input validation / bounds enforcement, Lifetime / state management Notes
CVE-2025-49721 fastfat.sys Input validation / bounds enforcement Notes
CVE-2025-49661 afd.sys Input validation / bounds enforcement Notes
CVE-2025-49659 tdx.sys Input validation / bounds enforcement, Lifetime / state management Notes
CVE-2025-47982 storvsp.sys Input validation / bounds enforcement Notes
CVE-2025-32713 clfs.sys Input validation / bounds enforcement Notes
CVE-2025-32709 afd.sys Input validation / bounds enforcement Notes
CVE-2025-32706 clfs.sys Input validation / bounds enforcement, Lifetime / state management Notes
CVE-2025-32701 clfs.sys Input validation / bounds enforcement, Lifetime / state management Notes
CVE-2025-30385 clfs.sys Input validation / bounds enforcement, Lifetime / state management Notes
CVE-2025-29838 executioncontext.sys Lifetime / state management, Reachable IOCTL or IRP surface hardening Notes
CVE-2025-29824 clfs.sys Lifetime / state management Notes
CVE-2025-29811 mbbcx.sys Input validation / bounds enforcement Notes
CVE-2025-26639 usbprint.sys Unconfirmed from supplied evidence Notes

Building PoCs

Requires MSVC. Run from a Visual Studio x64 developer prompt or set up the environment manually:

"C:\Program Files\Microsoft Visual Studio\2022\Community\VC\Auxiliary\Build\vcvars64.bat"
cd research\poc\CVE-2026-25176
build.bat

About

Windows kernel vulnerability research: PoC and analysis notes

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages