discovered 03 Aug 2026
CVE-2021-27965
→ View on GitHubCVE-2021-27965 is a proof-of-concept (PoC) exploit targeting a local privilege escalation vulnerability in the MICSYS Windows driver, MsIo64.sys. This tool leverages stack-based buffer overflow in the driver's IOCTL dispatch routine, allowing arbitrary physical memory mapping, port access, and potential system crashes. Notable features include the ability to execute IOCTL requests that bypass Windows security mechanisms, facilitating unauthorized access to system-level operations.