Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CVE-2026-49176_LPE_POC — Local privilege-escalation proof of concept for the Windows WalletService vulnerability fixed in July 2026. | Kitploit
ツール/GitHubGitHub/davidcarliez/cve-2026-49176_lpe_poc
Privilege EscalationVulnerability AnalysisExploitationPenetration TestingBinary Exploitation
GitHubdavidcarliez/cve-2026-49176_lpe_poc

CVE-2026-49176_LPE_POC

Local privilege-escalation proof of concept for the Windows WalletService vulnerability fixed in July 2026.

リポジトリを見る

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
48151ヶ月前未レビュー
要求された言語のコンテンツは利用できません。英語版を表示しています。

CVE-2026-49176 SYSTEM Shell PoC

Local privilege-escalation proof of concept for the Windows WalletService vulnerability fixed in July 2026.

Technical write-up: CVE-2026-49176 Exploit Development: WalletService to SYSTEM.

A standard user creates a Wallet ESE database containing a persisted callback and redirects their Documents known folder to it. Vulnerable WalletService opens the database as LocalSystem with persisted callbacks enabled, causing ESE to load the supplied DLL. The payload starts a command prompt as SYSTEM in the active desktop session.

Run

On a vulnerable Windows 11 system, open a non-elevated PowerShell and run:

root@kitploit:~
powershell.exe -ExecutionPolicy Bypass -File .\trigger.ps1

Alternatively, double-click run.cmd. A shell should open and print nt authority\system.

To rebuild the included binaries, install the Visual Studio C++ build tools and run:

root@kitploit:~
powershell.exe -ExecutionPolicy Bypass -File .\build.ps1

Tested on Windows 11 25H2 build 26200.8737.

Root cause

WalletService resolves FOLDERID_Documents while impersonating the caller, then reverts to LocalSystem before opening <Documents>\Wallet\wallet.db. It accepts a caller-created database and enables ESE persisted callbacks. Opening the Cards table resolves the callback path stored in the database schema and loads the specified DLL as SYSTEM.

ツールをダウンロード