
Windows 11-first educational lab for studying CVE-2025-1974 in ingress-nginx. Provides safe attack emulation and defense validation with local Kubernetes cluster, version assessment, and report generation for coursework and demos.
Windows 11-first educational repository for studying CVE-2025-1974 in a safe, non-weaponized ATTACK + DEFENSE lab. The project is designed for university coursework, team demos, and report-ready screenshots. It emphasizes clean-room implementation, local-only validation, and a red-team-style attack emulation that never becomes a real exploit.
This lab encodes the official baseline that CVE-2025-1974 affects ingress-nginx, with affected versions < 1.11.0, 1.11.0 through 1.11.4, and 1.12.0; fixed versions 1.11.5, 1.12.1, and later releases. It also reflects the official temporary mitigation of disabling the Validating Admission Controller until an upgrade is completed.
This repository intentionally does not implement, port, or operationalize exploit code. Instead, it provides a safe attack-flow emulator that demonstrates the stages a defender would reason about:
The attack path is represented through sanitized fixtures, local state, and simulator stage markers only. No malicious AdmissionReview payloads, code execution payloads, shells, config injection, or exploit delivery mechanisms are included.
flowchart LR
A["PowerShell Wrappers<br/>Windows 11-first UX"] --> B["Python CLI<br/>app.main"]
B --> C["Preflight Checks<br/>Windows, Docker, kubectl, kind, Python 3.11"]
B --> D["Cluster Assessment<br/>kind + kubectl on localhost"]
B --> E["Attack Simulator<br/>sanitized fixtures only"]
B --> F["Mitigation Checks<br/>version + admission state"]
B --> G["Detections<br/>lab-specific simulated indicators"]
E --> H["reports/attack_simulation.log"]
F --> I["reports/defense_scan.json"]
G --> J["reports/timeline.csv + timeline.json"]
H --> K["Markdown Report Writer"]
I --> K
J --> K
K --> L["reports/latest-report.md"]
Track A: Attack Emulation
Runs a screenshot-friendly simulator that behaves like an attacker workflow without performing exploitation.Track B: Defense Validation
Performs real local checks against a disposable lab cluster and assesses version and mitigation posture.Windows 11-first
Every major workflow has a PowerShell wrapper and Python 3.11 CLI equivalent.Reporting
Generates Markdown, JSON, CSV, and console transcripts suitable for class submission and demonstrations.kubectlkindpwsh ./scripts/setup-win11.ps1
pwsh ./scripts/start-lab.ps1
pwsh ./scripts/run-defend-scan.ps1
pwsh ./scripts/run-attack-sim.ps1
pwsh ./scripts/generate-report.ps1
python -m app.main preflight
python -m app.main defend-scan
python -m app.main attack-sim
python -m app.main report
python -m app.main cleanup
pwsh ./scripts/setup-win11.ps1
pwsh ./scripts/start-lab.ps1
pwsh ./scripts/run-attack-sim.ps1
pwsh ./scripts/run-defend-scan.ps1
pwsh ./scripts/generate-report.ps1
pwsh ./scripts/cleanup.ps1
============================================================
CVE-2025-1974 Windows 11 Attack + Defense Lab
============================================================
[PRECHECK] Windows 11 assumptions .............. PASS
[PRECHECK] Docker Desktop ...................... PASS
[PRECHECK] kubectl ............................. PASS
[PRECHECK] kind ................................ PASS
[PRECHECK] Python 3.11 ......................... PASS
[SCAN] Cluster name: cve-2025-1974-lab
[SCAN] ingress-nginx detected .................. YES
[SCAN] Controller version ...................... 1.11.4
[SCAN] Validating Admission Controller ......... ENABLED
[SCAN] Version assessment ...................... AFFECTED
[SCAN] Risk summary ............................ Upgrade to 1.11.5+ or 1.12.1+ and disable admission until upgraded.
[SIM] ATTACK_PATH_IDENTIFIED
[SIM] VALIDATION_PATH_REACHED
[SIM] DEFENSE_MISSING
[SIM] SIMULATED_RISK_CONFIRMED
[REPORT] Markdown report written to reports/latest-report.md
The attack-emulation flow is intentionally non-weaponized:
ingress-nginx appears present.ATTACK_PATH_IDENTIFIED and SIMULATED_RISK_CONFIRMED.MITIGATION_PRESENT, ATTACK_PATH_BLOCKED, and UPGRADE_REQUIRED instead.reports/.The defense-validation flow is allowed to perform real local checks:
kind cluster named cve-2025-1974-lab.ingress-nginx is present and attempt to infer the version from deployment images.pwsh ./scripts/cleanup.ps1
This removes the disposable kind cluster if present and clears generated report artifacts while preserving repository structure.
kubectl and local cluster state.This project conceptually references the public repository zulloper/CVE-2025-1974 by GitHub user @zulloper for historical/contextual study only. No offensive code has been copied into this repository.
Acknowledgements to Nir Ohfeld, Ronen Shustin, Sagi Tzadik, and Hillai Ben-Sasson from Wiz for responsibly disclosing the vulnerabilities, as recognized in official Kubernetes materials.
This repository is an independent clean-room educational lab for Windows 11 and is not affiliated with or endorsed by @zulloper, Wiz, Kubernetes, or the ingress-nginx maintainers.