Not a Pwn2Own bug

More in General
- Out-of-bounds write in ntfs!PageUpdateAnalysis
A heap buffer overflow vulnerability exists in the ntfs!PageUpdateAnalysis function of the Microsoft Windows NTFS driver.…
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- VMkatz: a hidden threat to virtual infrastructure 🫣
In 2026, a tool called VMkatz was published. In terms of functionality, it resembles the widely…
- ⚠️ Enabled Wi-Fi debugging — got Mamont
⚠️ Turned on Wi-Fi debugging — got Mamont In early May, a vulnerability CVE-2026-0073 was discovered…
Not a Pwn2Own bug 🙂
CVE-2024-43641: a CWE-190 type error allowed overflowing the reference count on a _CM_KEY_SECURITY instance. The vulnerable code was located in ntoskrnl.exe — in the CmpSetSecurityDescriptorInfo function (screenshot 1).
In order to reach the vulnerable code, it is necessary to open or create a registry key in transaction mode. This can be done via the RegCreateKeyTransacted function. Since there is no limit on the number of operations that can be recorded within a single transaction, we can successively call the NtSetSecurityObject function. And each such call will increment the reference count by 1.
In order for the vulnerability to “detonate,” it is necessary to wrap the reference count value around so that its value becomes less than the actual number of operations recorded within the transaction. If this condition is met, then after the transaction the _CM_KEY_SECURITY cell will be freed before the operations that need to be completed have finished, which will lead to use-after-free (screenshot 2).
The third screenshot shows part of the CmpDereferenceSecurityNode function responsible for decrementing the reference count and freeing _CM_KEY_SECURITY.
🩹 About the patch
The patch reworked how the Configuration Manager (CM) subsystem works with references to _CM_KEY_SECURITY, adding at least two new functions — CmpKeySecurityDecrementReferenceCount and CmpKeySecurityIncrementReferenceCount, which will now issue a bugcheck if the reference count becomes equal to zero or if after incrementing it is less than before (screenshot 4).
Fortunately, the vulnerability is hardly likely to be classifiable as exploitable, since overflowing the reference count by successively incrementing it by 1 would require a very long time, and the window within which we have the opportunity to “slip in” something is too small and uncontrollable.



#cve #escvr
@ptescalator
More in General
- Out-of-bounds write in ntfs!PageUpdateAnalysis
A heap buffer overflow vulnerability exists in the ntfs!PageUpdateAnalysis function of the Microsoft Windows NTFS driver.…
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- VMkatz: a hidden threat to virtual infrastructure 🫣
In 2026, a tool called VMkatz was published. In terms of functionality, it resembles the widely…
- ⚠️ Enabled Wi-Fi debugging — got Mamont
⚠️ Turned on Wi-Fi debugging — got Mamont In early May, a vulnerability CVE-2026-0073 was discovered…






