[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f_wjNbQJSwQqu8D4vwgA1ED3IrpTduDOTX4Mw3Pdg8Io":3},{"article":4,"iocs":36,"watch_terms":37},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":26,"category":27,"article_tags":30},"9f3df0de-fe02-48e7-84d5-d1ddce799fe6","WHQL-signed Windows kernel driver that hands any user-mode caller an arbitrary memory read primit...","whql-signed-windows-kernel-driver-that-hands-any-user-mode-caller-an-arbitrary-m-8098f3","WHQL-signed Windows kernel driver that hands any user-mode caller an arbitrary memory read primitive\n\nThis primitive is basically tailor-made for credential stealers i.e. LSASS dump\n\n- Opens as \\.\\devhost - no ACL beyond a device handle\n- Exposes the kernel page-table root at https:\u002F\u002Ft.co\u002FI05IS2G5JI","A Windows kernel driver signed by Microsoft's WHQL certification has been discovered to expose an arbitrary memory read primitive accessible to any user-mode caller without ACL restrictions. The vulnerability allows attackers to read kernel memory and extract credentials from LSASS, making it particularly dangerous for credential theft attacks. The driver exposes the kernel page-table root, effectively bypassing security boundaries.","WHQL-signed Windows kernel driver exposes arbitrary memory read primitive to user-mode processes.",null,"https:\u002F\u002Fx.com\u002Fnextronresearch\u002Fstatus\u002F2046972294325494182","https:\u002F\u002Fpbs.twimg.com\u002Fmedia\u002FHGhOSpvWoAA2SnP.jpg","2026-04-22T15:20:00+00:00","2026-04-22T16:00:12.602698+00:00",9,[18,21,24],{"name":19,"type":20},"Microsoft","vendor",{"name":22,"type":23},"Windows Kernel","technology",{"name":25,"type":23},"WHQL","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":26,"icon":11,"name":28,"slug":29},"Vulnerabilities","vulnerabilities",[31],{"category":32},{"id":33,"icon":11,"name":34,"slug":35},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",[],[19]]