CVE-2015-2291 affects the 32-bit and 64-bit Intel Ethernet diagnostics drivers for Windows before version 1.3.1.0. Local users can trigger denial of service or possibly execute arbitrary code with kernel privileges through crafted IOCTL requests using control codes 0x80862013, 0x8086200B, 0x8086200F, or 0x80862007. Exploitation through Bring Your Own Vulnerable Driver (BYOVD) techniques has demonstrated kernel-memory read/write access, process-token manipulation, and malicious kernel-driver deployment.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
Repository contains a Windows local privilege escalation PoC for CVE-2015-2291 targeting Intel's iqvw64e.sys (device \\.\Nal). Structure: (1) README.md explains reverse engineering of the driver's IRP_MJ_DEVICE_CONTROL handler, the IOCTL 0x80862007 path, and a jump-table dispatch where index 0x33 triggers an internal memmove-like routine. This yields an arbitrary kernel memory copy primitive, which is wrapped into read64/write64 helpers. (2) main.cpp is the operational exploit: it enumerates kernel drivers to find the ntoskrnl.exe base, loads a local ntoskrnl.exe to resolve PsInitialSystemProcess and compute its kernel address, uses the memmove primitive to read the SYSTEM process EPROCESS and its Token, walks the ActiveProcessLinks list to find the current process EPROCESS by UniqueProcessId, overwrites the current process Token with the SYSTEM token (token stealing), then launches powershell.exe. The exploit is build-specific due to hardcoded EPROCESS offsets for Windows 10 x64 22H2 (19045.6466). No network IOCs are present; all interaction is local via the device driver and kernel memory primitives.
This repository provides a detailed write-up and fully functional local privilege escalation exploit for CVE-2015-2291, targeting the Intel Ethernet diagnostics driver (IQVW32.sys/IQVW64.sys) on Windows 7 SP1 and Windows 10 20H2 (both 64-bit). The exploit is implemented in C and assembly, with separate codebases for Windows 7 and Windows 10. The main exploit logic is in 'exploit.c', which interacts with the vulnerable driver via the DeviceIoControl API using the IOCTL code 0x80862007. The exploit leverages the lack of proper input validation in the driver to perform arbitrary memory operations in kernel space, ultimately overwriting function pointers in the HalDispatchTable to execute custom kernel shellcode. The shellcode steals the SYSTEM process token and assigns it to the current process, resulting in a SYSTEM shell. The repository includes all necessary source files, project files for Visual Studio, and detailed technical documentation in the README. The exploit is operational and demonstrates a real-world local privilege escalation technique using a BYOVD (Bring Your Own Vulnerable Driver) approach.
This repository is a proof-of-concept (PoC) exploit for CVE-2015-2291, a privilege escalation vulnerability in the Intel Ethernet diagnostics driver (iqvw64e.sys) on Windows. The exploit is implemented in C++ and consists of two main code files: 'intelExplo.cpp' (main logic) and 'intelExplo.hpp' (definitions and helper functions/structs). The exploit interacts with the driver via the device interface '\\.\Nal' and leverages IOCTLs to perform arbitrary kernel memory read/write operations. By manipulating kernel memory, the exploit locates the SYSTEM process token and overwrites the current process token, effectively granting SYSTEM privileges to the exploit process. It then spawns a SYSTEM shell (cmd.exe). The code also includes additional functionality for physical-to-virtual address translation and mapping physical memory, which can be used for arbitrary kernel memory access. The exploit requires the vulnerable driver to be loaded and accessible, and is intended for local privilege escalation on Windows systems.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability in the Intel Ethernet diagnostics driver, iqvw64e.sys, abused in BYOVD attacks to disable endpoint detection and response from kernel space. The article connects MANTLEMAZE to the driver through a PDB path, but does not confirm that MANTLEMAZE exploits the vulnerability.
A vulnerability in the Intel Ethernet diagnostics driver, iqvw64e.sys, abused in BYOVD attacks to disable EDR from kernel space. The article connects the driver to MANTLEMAZE through an embedded PDB path, but does not establish that MANTLEMAZE successfully exploits the vulnerability.
An improper input-validation vulnerability in the Intel Ethernet Diagnostics Driver, iqvw64.sys. The article reports CVSS 7.8, CISA KEV inclusion, and use in ransomware campaigns. It is discussed as a known-driver comparison and a defensive testing example.
A vulnerability in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys) that can allow denial of service or possible arbitrary code execution with kernel privileges, and was used by Scattered Spider in a bring-your-own-vulnerable-driver style attack to deploy a malicious kernel driver.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.