BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Chaining Logical Bugs for Reliable Windows LPE\n   T
 ags: DEF CON Official Talk | Demo 💻 | Exploit 🪲\n   When: Sunday\, A
 ug 9\, 13:00 - 13:59 PDT\n   Where: LVCCW Level 1 Hall 3 903 (Main Track 5
 ) and DCTV-5 - [1]Map\n\n   Description:\n\n   Modern Windows exploit miti
 gations have made memory corruption\n   significantly harder\, but reliabl
 e privilege escalation still emerges\n   from a quieter class of bugs: log
 ical flaws in privileged components.\n   This talk shows how low impact Wi
 ndows bugs become practical SYSTEM\n   exploits when treated as reusable p
 rimitives over privileged\n   resources.\n\n   We will walk through two di
 stinct LPE chains to illustrate this\n   concept. First\, we demonstrate a
  novel LPE approach achieved by\n   chaining service-level process termina
 tion with arbitrary file\n   deletion. Second\, we explore another powerfu
 l LPE path that leverages\n   kernel- and task-driven registry creation an
 d deletion primitives\,\n   ultimately turning attacker-controlled registr
 y state into code\n   execution via Performance DLL hijacking.\n\n     * Z
 DI-24-1098:\n       https://www.zerodayinitiative.com/advisories/ZDI-24-10
 98/\n\n     * ZDI-24-451 / CVE-2024-30033:\n       https://www.zerodayinit
 iative.com/advisories/ZDI-24-451/\n\n     * CVE-2025-60705: Windows Client
 -Side Caching Elevation of Privilege\n       Vulnerability\n\n     * CVE-2
 025-59512: Windows Arbitrary Registry Deletion Elevation of\n       Privil
 ege Vulnerability\n\n     * Public Microsoft / MSRC security update refere
 nces for patched\n       issues\n\n     * itm4n\, "Windows RpcEptMapper Se
 rvice Insecure Registry Permissions\n       EoP": https://itm4n.github.io/
 windows-registry-rpceptmapper-eop/\n\n     * itm4n\, "An Unconventional Ex
 ploit for the RpcEptMapper Registry\n       Key Vulnerability":\n       ht
 tps://itm4n.github.io/windows-registry-rpceptmapper-exploit/\n\n   Speaker
 s:Bocheng "Crispr" Xiang\,HeeChan "heegong123" Kim\n\n   SpeakerBio:  Boch
 eng "Crispr" Xiang\, Fudan Univeristy\n\n   Bocheng Xiang (@crispr_x) is a
  PhD candidate at Fudan University. He\n   is listed on the MSRC MVR 2024/
 2025 and ranked Top #20 on the MSRC\n   2024 Q3 Windows Leaderboard. He ha
 s published papers at USENIX\n   Security 2025\, and his works have been a
 ccepted by PoC2025\,\n   re//verse2026 and BlackHat USA/Europe.\n\n   Spea
 kerBio:  HeeChan "heegong123" Kim\, TeamH4C\n\n   HeeChan Kim is a securit
 y researcher and a student at Soongsil\n   University\, specializing in Wi
 ndows OS internals and Local Privilege\n   Escalation (LPE). As a winner o
 f the DEF CON 33 CTF with team MMM and\n   a member of TeamH4C\, he active
 ly hunts for zero-days and persistent\n   logical flaws within complex OS 
 architectures. He has previously\n   presented his Windows LPE research at
  POC and RE//verse.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260809T205900Z
DTSTART:20260809T200000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 903 (Main Track 5) and DCTV-5
SUMMARY:Chaining Logical Bugs for Reliable Windows LPE
END:VEVENT
END:VCALENDAR
