Daily Dark Web
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
Daily Dark Web
No Result
View All Result
Home Vulnerability

Threat Actor Claims to Sell Zero-Day LPE Exploit for Windows 8.1, 10, and 11

June 19, 2024
Reading Time: 1 min read
Threat Actor Claims to Sell Zero-Day LPE Exploit for Windows 8.1, 10, and 11

A threat actor is allegedly selling a zero-day Local Privilege Escalation (LPE) exploit targeting Windows 8.1, 10, and 11. This exploit purportedly leverages a race condition vulnerability in the Windows kernel, specifically designed for x64 systems. It claims to elevate the rights of any already running process to SYSTEM level.

For the latest Windows 11, the exploit is said to use the I/O Ring technique, while for older versions, it allegedly achieves elevation by overwriting the PreviousMode in the _KTHREAD structure. According to the seller, the exploit is written in C and developed using Visual Studio 2019. The sale package purportedly includes an exploit project and a test example that launches cmd.exe, elevating console rights after a short period. The compiled exploit’s size is approximately 16KB.

Details of the Claim:
  • Target: Windows 8.1, 10, and 11
  • Vulnerability: Race condition in the Windows kernel
  • System Compatibility: x64 systems
  • Implementation: C in Visual Studio 2019
  • Functionality: Allegedly elevates rights to SYSTEM for any running process
  • Exploit Techniques:
    • Windows 11: I/O Ring technique
    • Older versions: Overwriting PreviousMode in _KTHREAD
  • Package Includes: Exploit project and test example
  • Compiled Size: ~16KB
  • Price: $150,000 in cryptocurrency
Tags: 0dayexploitLPEWin_ExWindows
ShareTweet

Related Posts

CPUID Website Compromised: CPU-Z and HWMonitor Serve Malware
Vulnerability

CPUID Website Compromised: CPU-Z and HWMonitor Serve Malware

April 10, 2026
Axios npm Package Compromised in Supply Chain Attack
Vulnerability

Axios npm Package Compromised in Supply Chain Attack

March 31, 2026
Critical Figma MCP Server Flaw Allows Remote Code Execution
Vulnerability

Critical Figma MCP Server Flaw Allows Remote Code Execution

October 8, 2025
Oracle Patches CVE−2025−61882
Vulnerability

Oracle Patches CVE−2025−61882

October 6, 2025
Shai-Hulud Worm Infects Over 500 NPM Packages in Sophisticated Supply Chain Attack
Vulnerability

Shai-Hulud Worm Infects Over 500 NPM Packages in Sophisticated Supply Chain Attack

September 17, 2025
WinRAR Zero-Day RCE Vulnerability Allegedly for Sale for $65,000
Vulnerability

WinRAR Zero-Day RCE Vulnerability Allegedly for Sale for $65,000

September 8, 2025
Next Post
Threat Actor Claims to Sell 30 Million User Records from Australian Ticket Vendor TEG

Threat Actor Claims to Sell 30 Million User Records from Australian Ticket Vendor TEG

Global Consulting Giant Accenture Allegedly Hit by Cyberattack

Global Consulting Giant Accenture Allegedly Hit by Cyberattack

Recommended Stories

🇯🇴 Jordan – Al-Ettifag Academy

🇯🇴 Jordan – Al-Ettifag Academy

November 27, 2025
Sonofet Data Breach Exposes User and Company Information

Sonofet Data Breach Exposes User and Company Information

October 1, 2025
Private Source Code for Fructose Checker Reportedly Leaked Online

Private Source Code for Fructose Checker Reportedly Leaked Online

January 12, 2025

Popular Stories

  • SudamericaData Breach Exposes Over 1TB of Argentine Records

    SudamericaData Breach Exposes Over 1TB of Argentine Records

    0 shares
    Share 0 Tweet 0
  • Threat Actor Claims Sale of Dell Database Containing 49 Million Customer Records

    0 shares
    Share 0 Tweet 0
  • SUUMO, CHINTAI, At Home, HOME’S Suffer Data Breach

    0 shares
    Share 0 Tweet 0
  • Financial Tech Giant SilverLake Axis Allegedly Breached – 423GB of Data for Sale

    0 shares
    Share 0 Tweet 0
  • Telekom Serbia Investigates Leak of 160,000 Customer Records

    0 shares
    Share 0 Tweet 0
Daily Dark Web

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

No Result
View All Result
  • About Us
  • Home
  • Newsletter
  • Privacy Policy

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?