When you forgot to tell Claude about C̵a̵l̵l̵b̵a̵c̵k̵ ̵O̵b̵j̵e̵c̵t̵s̵.̵ ̵W̵i̵n̵3̵2̵ ̵C̵a̵l̵l̵o̵u̵t̵s̵.̵ ̵E̵x̵t̵e̵n̵s̵i̵o̵n̵ ̵H̵o̵s̵t̵s̵.̵ ̵A̵P̵I̵ ̵S̵e̵t̵s̵.̵ Build a 8th mechanism to pass pointers between the kernel and Win32k.sys.
Chief Technical Innovation Officer @crowdstrike. Windows Internals author and trainer. He/Him. RTs are not endorsements, opinions are my own.
- I have literally two CVEs over the last decade with the same bug, in the same place, again, and again (and ten other researchers have ten more). It’s insane. When I still taught seminars I used to tell my classes “just scan memory for kernel pointers each build”.Wrote up CVE-2026-50416. win32k maps the desktop heap into every process. Offset 0x100 hands out a raw kernel session pool pointer. Readable from Low IL, AppContainer, even a zero capability LPAC. github.com/karollooool/CV…
- Very excited to see the talent we continue to bring together working on the next generation of our products.I'm thrilled to share that I am joining @CrowdStrike, along with a few of my colleagues I’ve most loved building with. When we founded @prequel_dev in 2023, we set out to change how teams find and fix security and reliability problems. Joining @CrowdStrike, a company I’ve long
- This information class was added only a few years ago. In the age of trillion dollar spending on AI code reviews and security, codeQL, KASAN and more, the world’s leading operating system kernel still added code to increment an arbitrary user controlled pointer in a system callGitHub - orinimron123/CVE-2026-40369-EXPLOIT: Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browsers render process sandbox · GitHub github.com/orinimron123/C…




