Sale of an LPE exploit (Ring 3 → SYSTEM) with UAC bypass and popular AV evasion

Dark Web2026-06-19, 12:10
For informational purposes only
Type of vulnerability: Local Privilege Escalation Affected OS: Windows (demonstration on Windows 10/11) Privileges obtained: SYSTEM
The seller offers an exploit that, according to the description, fully implements the complete chain of "UAC bypass → escalation to SYSTEM" entirely in userland - without kernel modules, without loading drivers, and without kernel exploits. The announcement includes a video PoC and screenshots.
One of the screenshots shows the output of whoami /priv with a full set of SYSTEM privileges (SeAssignPrimaryToken, SeTcb, SeDebug, SeImpersonate, etc.) against the active Kaspersky Plus in scanning mode.
According to the seller, the tool was tested against Kaspersky Plus and Bitdefender. Additionally, he is ready to perform a demonstration against AV/EDR of the buyer's choice.
Vendors
Kaspersky
Bitdefender
Products
Bitdefender
Kaspersky Plus
Whoami
Windows 10
Windows 11