Daily Dark Web
  • Home
  • Cyber Attacks
  • DarkWeb News
  • Data Breaches
  • Vulnerability
  • Ransomware News
  • Unauthorized Accesses
  • Contact
No Result
View All Result
  • Home
  • Cyber Attacks
  • DarkWeb News
  • Data Breaches
  • Vulnerability
  • Ransomware News
  • Unauthorized Accesses
  • Contact
No Result
View All Result
Daily Dark Web
No Result
View All Result
Home Vulnerability

Threat Actor Claims to Sell Zero-Day LPE Exploit for Windows 8.1, 10, and 11

June 19, 2024
Reading Time: 1 min read
Threat Actor Claims to Sell Zero-Day LPE Exploit for Windows 8.1, 10, and 11

A threat actor is allegedly selling a zero-day Local Privilege Escalation (LPE) exploit targeting Windows 8.1, 10, and 11. This exploit purportedly leverages a race condition vulnerability in the Windows kernel, specifically designed for x64 systems. It claims to elevate the rights of any already running process to SYSTEM level.

For the latest Windows 11, the exploit is said to use the I/O Ring technique, while for older versions, it allegedly achieves elevation by overwriting the PreviousMode in the _KTHREAD structure. According to the seller, the exploit is written in C and developed using Visual Studio 2019. The sale package purportedly includes an exploit project and a test example that launches cmd.exe, elevating console rights after a short period. The compiled exploit’s size is approximately 16KB.

Details of the Claim:
  • Target: Windows 8.1, 10, and 11
  • Vulnerability: Race condition in the Windows kernel
  • System Compatibility: x64 systems
  • Implementation: C in Visual Studio 2019
  • Functionality: Allegedly elevates rights to SYSTEM for any running process
  • Exploit Techniques:
    • Windows 11: I/O Ring technique
    • Older versions: Overwriting PreviousMode in _KTHREAD
  • Package Includes: Exploit project and test example
  • Compiled Size: ~16KB
  • Price: $150,000 in cryptocurrency
Tags: 0dayexploitLPEWin_ExWindows
ShareTweet

Related Posts

Alleged TP-Link Exploit for Sale on Dark Web
Vulnerability

Alleged TP-Link Exploit for Sale on Dark Web

March 25, 2025
Alleged IntelX 0-Day Vulnerability for Sale on Dark Web
Vulnerability

Alleged IntelX 0-Day Vulnerability for Sale on Dark Web

March 26, 2025
Threat Actor Allegedly Selling Zero-Day Android RCE Exploit for $800,000
Cyber Attacks

Threat Actor Allegedly Selling Zero-Day Android RCE Exploit for $800,000

October 1, 2024
Threat Actor Offers Exploit for Magento 2 Vulnerability
Vulnerability

Threat Actor Offers Exploit for Magento 2 Vulnerability

March 26, 2025
A Threat Actor Alleged 0-Day Vulnerability in Popular WordPress Plugin
Vulnerability

A Threat Actor Alleged 0-Day Vulnerability in Popular WordPress Plugin

September 1, 2024
Threat Actor Claims to Sell “.url” Exploit Source Code for $10k
Vulnerability

Threat Actor Claims to Sell “.url” Exploit Source Code for $10k

August 4, 2024
Next Post
Threat Actor Claims to Sell 30 Million User Records from Australian Ticket Vendor TEG

Threat Actor Claims to Sell 30 Million User Records from Australian Ticket Vendor TEG

Global Consulting Giant Accenture Allegedly Hit by Cyberattack

Global Consulting Giant Accenture Allegedly Hit by Cyberattack

Recommended Stories

Threat Actor Allegedly Offers Database and Source Code of Egypt-Based Lucky App for Sale

Threat Actor Allegedly Offers Database and Source Code of Egypt-Based Lucky App for Sale

April 27, 2024
Alleged Data Breach at PT Haleyora Power Exposes Employee Information

Alleged Data Breach at PT Haleyora Power Exposes Employee Information

October 21, 2024
Threat Actor Claims to Leak Nokia Employee Data from Third Party Breach

Threat Actor Claims to Leak Nokia Employee Data from Third Party Breach

July 9, 2024

Popular Stories

  • Threat Actor Claims Sale of Dell Database Containing 49 Million Customer Records

    Threat Actor Claims Sale of Dell Database Containing 49 Million Customer Records

    0 shares
    Share 0 Tweet 0
  • Threat Actor Claims to Have Leaked Database Containing Personal Information of 5 Million Salvadoran Citizens

    0 shares
    Share 0 Tweet 0
  • Threat Actor Claims Sale of State Grid Corporation of China (SGCC) Data, World’s Largest Utility Company

    0 shares
    Share 0 Tweet 0
  • New ATM Malware Threatens European Banking Security

    0 shares
    Share 0 Tweet 0
  • CyberNiggers Group Allegedly Breaches HSBC and Barclays Banks, Compromising Extensive Databases and Source Code

    0 shares
    Share 0 Tweet 0
Daily Dark Web

Daily Dark Web© 2024

No Result
View All Result
  • Contact
  • Home
  • Newsletter
  • Privacy Policy

Daily Dark Web© 2024

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?