Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/zeromemoryex/cve-2025-26125
Privilege EscalationVulnerability AnalysisExploitationPost-ExploitationBinary Exploitation
GitHubzeromemoryex/cve-2025-26125

CVE-2025-26125

( 0day ) Local Privilege Escalation in IObit Malware Fighter

View Repository
1722311 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

Description

  • The PoC program exploits the IMFForceDelete driver which exposes an ioctl that allows unprivileged users to delete files and folders. We can turn this into a privilege escalation by using a technique explained by ZDI and Halov, which exploits the MSI rollback mechanism which is designed to maintain system integrity in case of issues. By deleting and recreating it with a weak DACL and fake RBF and RBS files we can gain the ability to make arbitrary changes to the system as NT AUTHORITY\SYSTEM.

VID

https://github.com/user-attachments/assets/58e343d2-97a4-4ca3-9deb-df911b717a57

Write-up

  • https://www.hackandhide.com/from-dos-to-privilege-escalation/

CREDITS

  • Halov
  • ZDI
  • vx-underground and #ifndef hjonk
Download Tool