Reverse-Engineering Windows Services for Full-Chain LPE

No ratings

Presented at RE//verse 2026 by

Do you trust Microsoft's "solved" security patches? We began by reversing the Windows Error Reporting (WerSvc) ALPC interface, securing a 0-day that yields a powerful primitive. However, this primitive alone was not a full LPE. With this weapon in hand, we began reverse-engineering the patch binaries of "solved" Windows LPEs. We discovered new bypass vulnerabilities (CVE-2024-30033, CVE-2024-38022, CVE-2025-54116) resulting from incomplete patches. This presentation is the chronicle of how, after dissecting historical LPE vulnerabilities in depth, we developed new bypass techniques that re-enabled these legacy bugs to be exploited, leading us to LPE again.