You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
kernel transaction manager
About this tag
The Kernel Transaction Manager (KTM) is a kernel-mode transaction engine in Windows that supports transactional features like Transactional NTFS (TxF) and transactional registry operations. Recent security research and advisories have highlighted privilege escalation vulnerabilities in KTM, including CVE-2025-53140, a use-after-free flaw that can be exploited by an authorized local attacker. At OffensiveCon 2025, researchers presented findings on overlooked KTM vulnerabilities, referred to as cookies, and demonstrated how they can be exploited. These discoveries underscore the importance of patching KTM-related issues to maintain system security.
Microsoft’s Security Response Center has published an advisory for CVE‑2025‑53140, a use‑after‑free vulnerability in the Windows Kernel Transaction Manager (KTM) that Microsoft says can be exploited by an authorized local attacker to elevate privileges on an affected system. Background /...
Cookie-based attacks and overlooked tokens have quietly lingered on the periphery of infosec conference talks for years, but recent research presented at OffensiveCon25 has shone a spotlight on the very heart of Windows 11's Kernel Transaction Manager (KTM). This kernel subsystem—once considered...
At OffensiveCon 2025, held at the Hilton Berlin, security researchers presented a groundbreaking analysis titled "Hunting For Overlooked Cookies In Windows 11 KTM And Baking Exploits For Them." This presentation delved into the intricacies of the Windows 11 Kernel Transaction Manager (KTM)...