
PoC di exploit LPE per Windows CLFS per la ricerca sulla sicurezza
🚨 EXPLOIT PoC — SOLO PER RICERCA DI SICUREZZA, ANALISI DELLE VULNERABILITÀ E SCOPI DIFENSIVI
🚨 PoC DI EXPLOIT — SOLO PER RICERCA DI SICUREZZA, ANALISI DELLE VULNERABILITÀ E FINI DIFENSIVI
CVE-2025-60709 è una vulnerabilità di escalation dei privilegi locali (LPE) nel driver CLFS.sys (Common Log File System) di Windows. Consente a un attaccante con esecuzione locale di codice di elevare i propri privilegi da utente standard a NT AUTHORITY\SYSTEM tramite un buffer overflow nel parsing dei contenitori CLFS, ottenendo una primitiva di scrittura arbitraria nella memoria del kernel.
Questo repository contiene due implementazioni:
| Campo | Dettaglio |
|---|---|
| CVE ID | CVE-2025-60709 |
| Tipo | Escalation dei privilegi locali (LPE) |
| Componente | CLFS.sys (driver Common Log File System) |
| Sistema di destinazione | Windows 11 24H2 (build 26100.3485+) |
| Architettura | Solo x64 |
| Vettore | Buffer overflow nel parsing dei contenitori CLFS |
| Impatto | Escalation a NT AUTHORITY\SYSTEM |
| Prerequisiti | Esecuzione locale di codice (utente standard) |
CVE-2025-60709/
├── CVE-2025-60709.c (5.3 KB, 157 líneas) — Exploit C original
├── CVE-2025-60709.go (9.2 KB, 285 líneas) — Port Go (demo educativa)
└── README.txt (4.2 KB, 132 líneas) — Documentación original
┌─────────────────────────────────────────────────────────────┐
│ CVE-2025-60709 LPE │
└─────────────────────────────────────────────────────────────┘
[1] EVASIÓN DE DEFENSAS
├─ KillETW() → Parchea EtwEventWrite en ntdll con RET (0xC3)
└─ KillAMSI() → Parchea AmsiScanBuffer en amsi.dll con RET (0xC3)
[2] HEAP GROOMING (preparación de memoria)
└─ GroomLookaside()
├─ Crea 4096 archivos: C:\Windows\Temp\groom_00000.blf
├─ Llama CreateLogFile() + AddLogContainer() por cada uno
└─ Agota lookaside lists → garantiza layout de heap predecible
[3] PRIMITIVA DE ESCRITURA ARBITRARIA — ClfsArbWrite(Address, Value)
├─ Construye buffer CLFS malformado (0x102010 bytes)
│ ├─ Firma válida CLFS en +0x00: 0x0201
│ ├─ Sector size shift en +0x14: 2
│ ├─ First client region en +0x28: 0x100
│ ├─ cbRecord OVERSIZED en +0x100: 0xFF00 (64 KB > datos reales)
│ ├─ Marcador shadow zone en +0x9A8: 0x13371337
│ └─ CClfsContainerContext falso en offset (0xFF00 + 0x100):
│ ├─ pContainer = TargetAddress - 0x10
│ └─ cbContainer = Value (dato a escribir)
├─ Calcula checksum CLFS correcto (driver lo valida)
├─ Escribe contenedor malformado → C:\Windows\Temp\evil.blf
├─ Crea log apuntando a evil.blf
├─ Llama ClfsReadRestartArea() → dispara parsing kernel
└─ Driver desborda buffer → escribe Value en Address ✓
[4] ROBO DE TOKEN SYSTEM
├─ Lee EPROCESS del proceso SYSTEM via PsInitialSystemProcess
└─ Extrae token en EPROCESS + EPROCESS_TOKEN (offset 0x4c0)
[5] ESCALACIÓN DE PRIVILEGIOS
└─ ClfsArbWrite(CurrentEprocess + 0x4c0, SystemToken)
└─ Sobreescribe token del proceso actual con token SYSTEM ✓
[6] EJECUCIÓN DE PAYLOAD C2
├─ VirtualAlloc(PAGE_EXECUTE_READWRITE)
├─ Copia shellcode beacon de 1789 bytes
├─ CreateThread() → ejecución como NT AUTHORITY\SYSTEM
└─ Beacon C2: IPv6 + DoH → fallback Gmail drafts
└─ sRDI + sleep obfuscation + ETW/AMSI ya parcheados
[7] PERSISTENCIA
└─ Sleep(INFINITE) → proceso mantiene token SYSTEM
| Campo | Offset | Descrizione |
|---|---|---|
EPROCESS_TOKEN | 0x4C0 | Token di sicurezza del processo |
EPROCESS_PID | 0x440 | Process ID (PID) |
EPROCESS_LINKS | 0x448 | Lista collegata dei processi attivi |
EPROCESS_NAME | 0x5A8 | Nome del processo (ImageFileName) |
⚠️ Questi offset variano tra le build di Windows. Richiedono un aggiornamento per altre versioni.
Contenedor CLFS legítimo:
[Header 0x100 bytes][Record: cbRecord bytes de datos reales]
Contenedor malformado (evil.blf):
[Header válido][cbRecord=0xFF00 → kernel lee 65,280 bytes]
↓
Kernel overflow → llega a CClfsContainerContext falso
↓
pContainer = TargetKernelAddress - 0x10
cbContainer = ValueToWrite
↓
Driver usa estructura falsa → escribe ValueToWrite en TargetKernelAddress
CVE-2025-60709.c| Funzione | Scopo |
|---|---|
GetKernelBase() | ZwQuerySystemInformation(SystemModuleInformation) → base di ntoskrnl.exe |
KillETW() | VirtualProtect + sovrascrive EtwEventWrite in ntdll.dll con 0xC3 (RET) |
KillAMSI() | Carica amsi.dll + sovrascrive AmsiScanBuffer con 0xC3 (RET) |
GroomLookaside() | Crea 4096 log CLFS per esaurire le lookaside lists → heap deterministico |
ClfsArbWrite() | Nucleo dell'exploit — primitiva di scrittura arbitraria nel kernel |
main() | Orchestra l'attacco: ETW→AMSI→groom→token theft→arb write→beacon |
| Aspetto | Versione C | Versione Go |
|---|---|---|
| Tipo | Exploit funzionale (secondo la documentazione) | Solo demo educativa |
| API | Accesso diretto (ntdll, clfsw32, advapi32) | Wrapper syscall.NewLazyDLL() |
| Checksum CLFS | Algoritmo completo | Placeholder semplificato |
| Indirizzi kernel | Reali | Placeholder hardcoded (0x123456) |
| Payload C2 | Shellcode da 1789 byte | Byte NOP (0x90) di prova |
| Risultato atteso | Escalation a SYSTEM | Messaggio "Arb write failed (yeah)" |
Versione C (richiede Visual Studio Build Tools + Windows SDK):
cl /O1 /MT /link ntdll.lib advapi32.lib clfsw32.lib CVE-2025-60709.c
Versione Go (richiede Go 1.19+ su Windows x64):
go build -ldflags="-s -w" -o CVE-2025-60709.exe CVE-2025-60709.go