Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

SMAP is Pre-Disarmed: How a Stack Pivot That Shouldn't Work Revealed a Kernel-Wide Design Compromise

0
Medium
Published: 08/11/2026 (08/11/2026, 10:46:26 UTC)
Source: Reddit NetSec

Description

This research highlights a design compromise in the Windows kernel related to Supervisor Mode Access Prevention (SMAP). Specifically, it experimentally confirms that SMAP is effectively disabled during standard IOCTL dispatches, allowing a stack pivot into user-mode memory without triggering SMAP protections. This behavior stems from the Windows kernel not being originally built with SMAP in mind, and retrofitting it would require extensive changes. The finding is a confirmation of an architectural limitation rather than a newly discovered vulnerability with an active exploit.

Reddit Discussion

r/netsec·posted by u/Important_Map6928
00

While working through a kernel exploit chain on Windows 11, I noticed that a stack pivot into user-mode memory didn't trigger SMAP.

I wrote up three experiments to figure out why. Short version: the normal syscall entry path arrives with RFLAGS.AC=1. SMAP is effectively disabled for any code reached through a standard IOCTL dispatch. This aligns with what MSRC documented back in 2020 (the Windows kernel simply wasn't built with SMAP in mind, and retrofitting it would touch ~2,900 locations: here)

My conclusion isn't novel here. It's just an experimental confirmation of the architectural compromise on current builds. I just wanted to shine the light on this blind spot.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/11/2026, 11:26:12 UTC

Technical Analysis

The analysis focuses on the Windows kernel's handling of SMAP, a security feature intended to prevent kernel-mode code from accessing user-mode memory unintentionally. During normal syscall entry, the RFLAGS.AC bit is set to 1, which disables SMAP protections for code paths reached through standard IOCTL dispatches. This allows a stack pivot into user-mode memory without SMAP triggering, revealing a kernel-wide design compromise. The Windows kernel was not originally designed with SMAP enabled, and enabling it now would require modifying approximately 2,900 code locations. This research experimentally confirms the architectural limitation documented by Microsoft Security Response Center (MSRC) in 2020.

Potential Impact

The impact is a reduced effectiveness of SMAP protections in the Windows kernel during IOCTL dispatches, which could theoretically be leveraged in kernel exploit chains to bypass SMAP. However, this is an architectural design limitation rather than a direct vulnerability with known exploits in the wild. No active exploitation or specific attack vectors are described in the provided information.

Defensive Guidance

No official patch or remediation is indicated in the provided data. The research confirms an existing architectural compromise documented by Microsoft in 2020. Organizations should monitor vendor advisories for any future updates addressing SMAP enablement in the Windows kernel. Until then, no direct mitigation steps are provided or required based on this research.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
netsec
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a7b06cbbf8831d539a05e21

Added to database: 08/11/2026, 11:26:03 UTC

Last enriched: 08/11/2026, 11:26:12 UTC

Last updated: 08/11/2026, 15:41:02 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses