CVE-2023-38817

HIGH EXPLOITED

Inspect Element Ltd Echo.ac <5.2.1.0 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2023-38817 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including vxcall, SecSecBurger.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2023-38817, leveraging a vulnerable signed driver to achieve kernel-mode read/write memory operations from user-mode. The exploit uses MmCopyVirtualMemory and lacks proper access control over its IOCTLs, enabling privilege escalation.

Description

An issue in Inspect Element Ltd Echo.ac v.5.2.1.0 allows a local attacker to gain privileges via a crafted command to the echo_driver.sys component. NOTE: the vendor's position is that the reported ability for user-mode applications to execute code as NT AUTHORITY\SYSTEM was "deactivated by Microsoft itself."

Exploits (2)

nomisec WORKING POC 18 stars
by vxcall · poc
https://github.com/vxcall/kur

This repository contains a functional exploit for CVE-2023-38817, leveraging a vulnerable signed driver to achieve kernel-mode read/write memory operations from user-mode. The exploit uses MmCopyVirtualMemory and lacks proper access control over its IOCTLs, enabling privilege escalation.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Vulnerable driver (CVE-2023-38817)
No auth needed
Prerequisites: Vulnerable driver installed · Administrative privileges to load the driver
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by SecSecBurger · local
https://github.com/SecSecBurger/CVE-2023-38817

This is a functional exploit for CVE-2023-38817, demonstrating a local privilege escalation (LPE) via arbitrary kernel memory read/write operations. The code interacts with a vulnerable driver (EchoDrv) to escalate privileges by overwriting the current process's token with the system token.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Windows 10 22H2 (EchoDrv driver)
No auth needed
Prerequisites: Vulnerable driver (EchoDrv) must be loaded · Local access to the target system
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory
https://ioctl.fail/echo-ac-writeup/

Scores

CVSS v3 7.8
EPSS 0.0046
EPSS Percentile 35.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

VulnCheck KEV 2024-09-10
CWE
CWE-269
Status published
Products (1)
echo/anti_cheat_tool < 5.2.1.0
Published Oct 11, 2023
Tracked Since Feb 18, 2026