EIP-2026-115799
PRE-CVEMicrosoft Windows Kernel - 'NtQueryVirtualMemory(MemoryMappedFilenameInformation)' Double-Write Ring-0 Address Leak
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-115799. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit leverages a race condition in the NtQueryVirtualMemory system call to disclose kernel-mode Paged Pool allocation addresses. It uses two threads to exploit the 'double write' vulnerability, allowing the leakage of kernel pointers.
Description
Microsoft Windows Kernel - 'NtQueryVirtualMemory(MemoryMappedFilenameInformation)' Double-Write Ring-0 Address Leak
Exploits (1)
This exploit leverages a race condition in the NtQueryVirtualMemory system call to disclose kernel-mode Paged Pool allocation addresses. It uses two threads to exploit the 'double write' vulnerability, allowing the leakage of kernel pointers.