References https://www.hkcert.org/tc/security-bulletin/microsoft-windows-kernel-mode-driver-elevation-of-privilege-vulnerabilities-3 https://www1.szu.edu.cn/nc/view.asp?id=523 https://github.com/secwiki/windows-kernel-exploits https://www.fortra.com/resources/vulnerabilities/windows-kernel-mode-drivers-allow-elevation-privilege-ms12-047 https://www.anquanke.com/post/id/300942 https://bbs.kanxue.com/thread-277016.htm https://devco.re/blog/2024/10/05/streaming-vulnerabilities-from-windows-kernel-proxying-to-kernel-part2/ https://support.microsoft.com/en-us/topic/ms11-012-vulnerabilities-in-windows-kernel-mode-drivers-could-allow-elevation-of-privilege-865169e0-d625-c1e0-5f86-010d6ee1f0ab https://qkl.seebug.org/category/privilege-escalation https://research.qianxin.com/archives/2866 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-35250 https://github.com/SecWiki/windows-kernel-exploits/blob/master/README.md https://www.hkcert.org/tc/security-bulletin/microsoft-windows-kernel-mode-drivers-multiple-vulnerabilities-7
Related VulnerabilitiesPoCCVE-2026-58191: Appium base-driver <=10.6.0 - Reflected Cross-Site ScriptingPoCCVE-2026-58644: Microsoft SharePoint Server - WS-Federation BinaryFormatter Deserialization RCEMicrosoft SharePoint /_layouts/15/ToolPane.aspx 代码执行漏洞(CVE-2025-53770)Microsoft SharePoint Server /_trust/default.aspx 代码执行漏洞(CVE-2026-50522)Microsoft SharePoint Server JWT 权限绕过漏洞(CVE-2026-55040)Mage AI /api/kernels 未授权访问漏洞(CVE-2025-2129)Linux Kernel Fragnesia 本地权限提升漏洞(CVE-2026-46300)Linux Kernel "Copy Fail" 本地权限提升漏洞(CVE-2026-31431)Windows截图工具NTLM信息泄露漏洞(CVE-2026-33829)Gradio /static//windows/win.ini 文件读取漏洞 (CVE-2026-28414)Windows Shell Link 敏感信息泄露与欺骗漏洞(CVE-2026-25185)PoCCVE-2021-28480: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCCVE-2021-28481: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)