TGViewer
white2hack 📚 white2hack 📚 @w2hack · 12.8K subscribers
Post #8063 1.74K
Great analysis by NCC Group on CVE-2026-21236, a heap-based buffer overflow in the AFD.sys kernel driver

This blog post presents a patch diff, vulnerability analysis, and proof-of-concept generation of CVE-2026-21236 - a heap-based buffer overflow in afd.sys, the kernel-mode driver underpinning Windows socket operations.

Patched by Microsoft on February 11, 2026,
the vulnerability resides in the SAN connect handling path and carries an Elevation of Privilege impact, allowing a local attacker to corrupt kernel pool memory. The paper is presented from her point of view. We will also include a small section on AI, applied to patch diffing.

#reverse #windows
  • 👍 5
More from @w2hack
  1. Sep 23, 2026TECHNICAL ENGLISH FOR CYBERSECURITY. E-BOOK, Ivan Piskunov | White2hack, 2026 Practical Ha…
  2. Jun 3, 2026STAY CURIOUS. BUILD YOUR OWN. 🥷 "Hacking means exploring the limits of what is possible,…
  3. May 29, 2026📱 BASH БАЗА ДЛЯ КИБЕРБЕЗОПАНОСТИ, I.P. | White2Hack, 2026 (ver. 1.1), free editon
  4. May 29, 2026Starter Kit (ZIP) | BASH БАЗА ДЛЯ КИБЕРБЕЗОПАНОСТИ, I.P. | White2Hack, 2026 (ver. 1.1)
  5. May 29, 2026📱 BASH БАЗА ДЛЯ КИБЕРБЕЗОПАНОСТИ, I.P. | White2Hack, 2026 (ver. 1.1), free editon Выпусти…
  6. May 27, 2026НЕ ДЛЯ ВСЕХ. ДЛЯ ГОТОВЫХ ДВИГАТЬСЯ. Ты не тупой. У тебя просто нет плана. Жизнь одна и тай…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →