Skip to content

Exploit for CVE-2023-52271 in C++. The code exploits the vulnerable driver wsftprm.sys kernel driver 2.0.0.0, which allows kernel-level access to terminate running PPL processes.

Notifications You must be signed in to change notification settings

victoni/BYOVD-CVE-2023-52271-POC

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

7 Commits
 
 
 
 

Repository files navigation

Disclaimer: This repository contains code that is provided strictly for educational and research purposes only. DO NOT use this code on systems you do not own or have explicit permission to test. Any misuse of this code may violate local, national, or international laws.

CVE-2023-52271 POC

Exploit for CVE-2023-52271 in C++. The code exploits the vulnerable driver wsftprm.sys kernel driver 2.0.0.0, which allows kernel-level access to terminate running PPL processes. Mostly utilized for killing AV/EDR processes.

NVD Entry

Screenshot from 2026-01-21 21-56-31

About

Exploit for CVE-2023-52271 in C++. The code exploits the vulnerable driver wsftprm.sys kernel driver 2.0.0.0, which allows kernel-level access to terminate running PPL processes.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages