Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2022-26937 — Windows Network File System تعطل PoC | Kitploit
أدوات/GitHubGitHub/omair2084/cve-2022-26937
تحليل الثغرات الأمنيةالاستغلالأمن الشبكاتاستغلال الملفات الثنائية
GitHubomair2084/cve-2022-26937

CVE-2022-26937

Windows Network File System تعطل PoC

عرض المستودع
85227منذ 4 سنواتتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

إثبات المفهوم لتعطل نظام ملفات الشبكة في Windows

CVE-2022-26937

nt!KeBugCheckEx:
fffff803`8996efa0 48894c2408      mov     qword ptr [rsp+8],rcx ss:0018:ffffd000`d589ae60=0000000000000139
1: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure.  The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000002, Stack cookie instrumentation code detected a stack-based
	buffer overrun.
Arg2: ffffd000d589b180, Address of the trap frame for the exception that caused the BugCheck
Arg3: ffffd000d589b0d8, Address of the exception record for the exception that caused the BugCheck
Arg4: 0000000000000000, Reserved

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 1124

    Key  : Analysis.DebugAnalysisManager
    Value: Create

    Key  : Analysis.Elapsed.mSec
    Value: 34762

    Key  : Analysis.Init.CPU.mSec
    Value: 609

    Key  : Analysis.Init.Elapsed.mSec
    Value: 517613

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 77

    Key  : FailFast.Name
    Value: STACK_COOKIE_CHECK_FAILURE

    Key  : FailFast.Type
    Value: 2

    Key  : WER.OS.Branch
    Value: winblue_gdr

    Key  : WER.OS.Timestamp
    Value: 2014-02-21T19:52:00Z

    Key  : WER.OS.Version
    Value: 8.1.9600.17031


FILE_IN_CAB:  061622-6921-01.dmp

VIRTUAL_MACHINE:  VMware

BUGCHECK_CODE:  139

BUGCHECK_P1: 2

BUGCHECK_P2: ffffd000d589b180

BUGCHECK_P3: ffffd000d589b0d8

BUGCHECK_P4: 0

TRAP_FRAME:  ffffd000d589b180 -- (.trap 0xffffd000d589b180)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=00000000c0000001 rbx=0000000000000000 rcx=0000000000000002
rdx=ffffe000515c2010 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80158eeeb05 rsp=ffffd000d589b318 rbp=ffffd000d589b420
 r8=ffffe000515c2010  r9=0000000000000268 r10=ffffe000514df130
r11=ffffe0005188d010 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei ng nz ac po nc
nfssvr!_report_gsfailure+0x5:
fffff801`58eeeb05 cd29            int     29h
Resetting default scope

EXCEPTION_RECORD:  ffffd000d589b0d8 -- (.exr 0xffffd000d589b0d8)
ExceptionAddress: fffff80158eeeb05 (nfssvr!_report_gsfailure+0x0000000000000005)
   ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
  ExceptionFlags: 00000001
NumberParameters: 1
   Parameter[0]: 0000000000000002
Subcode: 0x2 FAST_FAIL_STACK_COOKIE_CHECK_FAILURE 

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  System

ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.

EXCEPTION_CODE_STR:  c0000409

EXCEPTION_PARAMETER1:  0000000000000002

EXCEPTION_STR:  0xc0000409

SYMBOL_NAME:  nfssvr!_report_gsfailure+5

MODULE_NAME: nfssvr

IMAGE_NAME:  nfssvr.sys

IMAGE_VERSION:  6.3.9600.16384

STACK_COMMAND:  .cxr; .ecxr ; kb

BUCKET_ID_FUNC_OFFSET:  5

FAILURE_BUCKET_ID:  0x139_MISSING_GSFRAME_nfssvr!_report_gsfailure

OS_VERSION:  8.1.9600.17031

BUILDLAB_STR:  winblue_gdr

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 8.1

FAILURE_ID_HASH:  {998b6b82-b64e-49ce-d962-6836c54aa899}

Followup:     MachineOwner
---------
تنزيل الأداة