Skip to content

[GHSA-8gh5-q362-whfc] Double free in Windows Kernel allows an authorized...#8798

Open
nikosecurity wants to merge 1 commit into
nikosecurity/advisory-improvement-8798from
nikosecurity-GHSA-8gh5-q362-whfc
Open

[GHSA-8gh5-q362-whfc] Double free in Windows Kernel allows an authorized...#8798
nikosecurity wants to merge 1 commit into
nikosecurity/advisory-improvement-8798from
nikosecurity-GHSA-8gh5-q362-whfc

Conversation

@nikosecurity

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3
  • Description
  • References
  • Source code location
  • Summary

Comments
Since this is my CVE, I wanted to try and clarify a few details that MSRC's advisory was inaccurate about. The CVSS that the Zero Day Initiative provided for this vulnerability is lower, but notes that this vulnerability leads to a scope change. In particular, you could use this vulnerability to execute code within Virtual Trust Level 1 (VTL1)'s secure kernel, which is a separate virtual partition from the base NT kernel, being VTL0 (with some referring to it as the "normal" world). As for the description, it is rather vague as there are many kernel components within the Windows kernel that are simply bundled under the "Windows Kernel" component umbrella, and I would like to make clarifications about the exact component this affects rather than keeping it vague.

I also would like to add the ZDI advisory and my proof-of-concept code to the list of references, as the ZDI advisory provides additional helpful details about the vulnerability, and my proof-of-concept code demonstrates how one can trigger the vulnerability as a kernel driver.

Lastly, I would like to mention that I cannot submit this improvement request without selecting an ecosystem and Windows does not appear. The selected ecosystem should be ignored as it is unrelated to this vulnerability.

@github-actions
github-actions Bot changed the base branch from main to nikosecurity/advisory-improvement-8798 July 24, 2026 01:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant