Kernel Primitives to Code Execution on Windows 11 VBS/HVCI/kCET (SSDT/SSDT Shadow hooks)
This session presents a modern Windows 11 exploit chain for achieving kernel code execution on systems with VBS, HVCI, and kCET enabled, using SSDT and Shadow SSDT hook-based techniques.
Beginning with a recap on Windows Kernel structures and components, then diving into vulnerable kernel driver behavior and vulnerability hunting, we will show how to identify and abuse kernel read/write primitives, reasoning about mitigation, and transform primitives into reliable kernel code execution.
The talk covers current exploit classes under VBS/HVCI/kCET, including data-only attacks and the reach of them when combined with data-only-gadgets, kernel object manipulation, suspended-thread based execution, COP/JOP and ROP in kernel context and SSDT and Shadow SSDT table-hooking techniques.
We will also introduce the custom tooling and plugins built during this research, explain why existing tools were insufficient, and release the tooling on GitHub. Case studies will include real-world vulnerabilities and zero-days discovered during the project.
The session ends with a live demo on a hardened Windows 11 system with VBS, HVCI, and kCET enabled, demonstrating a complete exploit chain resulting in NT AUTHORITY\SYSTEM access, data-only-gadgets and arbitrary kernel code execution through SSDT and Shadow SSDT hooks.
Exploit Writer, Reverse Engineer, Pentester, Ethical Hacker, OSCP, OSCE, Linux Specialist (15+ years ), worked at Core Security, NOD32, Homeland Security (ArCERT), ING Nederland Red Team, KPN Red Team , RaboBank Red Team, Avast Red Team and others financial and security related organisations.
$whoami:
http://packetstormsecurity.com/search/?q=juan+sacco
https://www.exploit-db.com/?author=6701
Certifications:
- OSCP
- OSCE
- Advanced Corelan Exploit Development
- Advanced IDA Pro by HexRays
Conferences I participated worldwide as speaker:
NoHat - Windows Kernel Exploitation Training
BSides Frankfurt - Subverting the Windows kernel with rootkits and exploits
Black Hat Europe – Exploit Pack
HITB ( Hack in The Box ) - Exploit Writing 64 Bits
Black Hat – Exploit Pack tool
And more..
Publications and CVE’s:
NetPerf Hewllet Packard - Buffer Overflow ROP
Ivanti CVE2019-10885 – Privilege Escalation
Whatsapp 2.18.31 – Remote memory corruption
Kaspersky KSN – Remote RCE
BOCHS 2.6-5 Local Buffer Overflow
WhatsApp 2.17.52 Memory Corruption
Asterisk 13.17.2~dfsg-2 - CVE-2017-17090
MAWK 1.3.3-17 Buffer Overflow
PaloAlto Firewall PAN-57659/95895 - CVE-2016-2219
Microsoft Word MTA Handler Remote Code Execution
Facebook - Bug Bounty
Microsoft - Bug Bounty
Microsoft Windows Server 2008 R2 (x64) - SrvOs2FeaToNt' SMB - CVE-2017-0143
OSX – Xcode-select 2.1.1 Buffer Overflow
EChat Server 2.5 Buffer Overflow
Cisco ASA VPN Remote - CVE-2014-2120
xMatters AlarmPoint APClient 3.2.0 Heap Buffer Overflow
xMatters AlarmPoint Java Web Server API 3.2.1 SQLi
Easy Server 3.1 Buffer Overflow
Mercadolibre Persistent Web Vulnerability
BitchX 1.x IRC Client Buffer Overflow
Blender 2.0x Remote Code Execution
Microsoft Reporting tool Buffer Overflow
CDRipper 2.x Buffer Overflow
IRSSI Client 0.6x Remove Code Execution
VCDGEAR – Buffer overflow
MP3Info – Stack based buffer overflow
Perfectview CRM – Stored XSS and SQLi
Mobile IRON – XSS and SMTP Bypass
and more..