Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2025-60709 — 보안 연구용 Windows CLFS LPE 익스플로잇 PoC | Kitploit
도구/GitHubGitHub/kondordevsecuritycorp/cve-2025-60709
Defensive ToolsPrivilege EscalationVulnerability AnalysisExploitationLearning & EducationPayload DevelopmentBinary Exploitation
GitHubkondordevsecuritycorp/cve-2025-60709

CVE-2025-60709

보안 연구용 Windows CLFS LPE 익스플로잇 PoC

저장소 보기
75개월 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

CVE Type Target Component C Go Research


🚨 EXPLOIT PoC — 보안 연구, 취약점 분석 및 방어 목적으로만 사용하십시오

🚨 EXPLOIT PoC — 보안 연구, 취약점 분석 및 방어 목적으로만 제공됩니다


🌐 언어

  • 🇪🇸 스페인어
  • 🇬🇧 영어

🇪🇸 스페인어 문서

설명

CVE-2025-60709은 Windows CLFS.sys(Common Log File System) 드라이버의 로컬 권한 상승(LPE) 취약점입니다. 로컬 코드 실행 권한이 있는 공격자는 CLFS 컨테이너 파싱의 버퍼 오버플로를 통해 일반 사용자에서 NT AUTHORITY\SYSTEM으로 권한을 상승시킬 수 있으며, 커널 메모리에 대한 임의 쓰기 프리미티브를 획득할 수 있습니다.

이 저장소에는 두 가지 구현이 포함되어 있습니다:

  • CVE-2025-60709.c — C 언어 원본 구현(Windows 네이티브 API 직접 접근)
  • CVE-2025-60709.go — Go 포트 (데모/교육용 버전 — 실제 취약점을 악용하지 않음)

🎯 취약점 세부 정보

필드세부 정보
CVE IDCVE-2025-60709
유형로컬 권한 상승(LPE)
구성 요소CLFS.sys(Common Log File System 드라이버)
대상 시스템Windows 11 24H2(빌드 26100.3485+)
아키텍처x64 전용
공격 벡터CLFS 컨테이너 파싱의 버퍼 오버플로
영향NT AUTHORITY\SYSTEM으로 권한 상승
전제 조건로컬 코드 실행(일반 사용자)

🏗️ 저장소 구조

CVE-2025-60709/
├── CVE-2025-60709.c    (5.3 KB, 157 líneas) — Exploit C original
├── CVE-2025-60709.go   (9.2 KB, 285 líneas) — Port Go (demo educativa)
└── README.txt          (4.2 KB, 132 líneas) — Documentación original

🔬 상세 기술 분석

전체 악용 흐름

┌─────────────────────────────────────────────────────────────┐
│                    CVE-2025-60709 LPE                       │
└─────────────────────────────────────────────────────────────┘

[1] EVASIÓN DE DEFENSAS
    ├─ KillETW()   → Parchea EtwEventWrite en ntdll con RET (0xC3)
    └─ KillAMSI()  → Parchea AmsiScanBuffer en amsi.dll con RET (0xC3)

[2] HEAP GROOMING (preparación de memoria)
    └─ GroomLookaside()
       ├─ Crea 4096 archivos: C:\Windows\Temp\groom_00000.blf
       ├─ Llama CreateLogFile() + AddLogContainer() por cada uno
       └─ Agota lookaside lists → garantiza layout de heap predecible

[3] PRIMITIVA DE ESCRITURA ARBITRARIA — ClfsArbWrite(Address, Value)
    ├─ Construye buffer CLFS malformado (0x102010 bytes)
    │    ├─ Firma válida CLFS en +0x00: 0x0201
    │    ├─ Sector size shift en +0x14: 2
    │    ├─ First client region en +0x28: 0x100
    │    ├─ cbRecord OVERSIZED en +0x100: 0xFF00 (64 KB > datos reales)
    │    ├─ Marcador shadow zone en +0x9A8: 0x13371337
    │    └─ CClfsContainerContext falso en offset (0xFF00 + 0x100):
    │         ├─ pContainer = TargetAddress - 0x10
    │         └─ cbContainer = Value (dato a escribir)
    ├─ Calcula checksum CLFS correcto (driver lo valida)
    ├─ Escribe contenedor malformado → C:\Windows\Temp\evil.blf
    ├─ Crea log apuntando a evil.blf
    ├─ Llama ClfsReadRestartArea() → dispara parsing kernel
    └─ Driver desborda buffer → escribe Value en Address ✓

[4] ROBO DE TOKEN SYSTEM
    ├─ Lee EPROCESS del proceso SYSTEM via PsInitialSystemProcess
    └─ Extrae token en EPROCESS + EPROCESS_TOKEN (offset 0x4c0)

[5] ESCALACIÓN DE PRIVILEGIOS
    └─ ClfsArbWrite(CurrentEprocess + 0x4c0, SystemToken)
       └─ Sobreescribe token del proceso actual con token SYSTEM ✓

[6] EJECUCIÓN DE PAYLOAD C2
    ├─ VirtualAlloc(PAGE_EXECUTE_READWRITE)
    ├─ Copia shellcode beacon de 1789 bytes
    ├─ CreateThread() → ejecución como NT AUTHORITY\SYSTEM
    └─ Beacon C2: IPv6 + DoH → fallback Gmail drafts
       └─ sRDI + sleep obfuscation + ETW/AMSI ya parcheados

[7] PERSISTENCIA
    └─ Sleep(INFINITE) → proceso mantiene token SYSTEM

EPROCESS 오프셋(Windows 11 24H2 빌드 26100.3485+)

필드오프셋설명
EPROCESS_TOKEN0x4C0프로세스 보안 토큰
EPROCESS_PID0x440프로세스 ID(PID)
EPROCESS_LINKS0x448활성 프로세스 연결 리스트
EPROCESS_NAME0x5A8프로세스 이름(ImageFileName)

⚠️ 이 오프셋은 Windows 빌드마다 다릅니다. 다른 버전에서는 업데이트가 필요합니다.


CLFS 버퍼 오버플로 메커니즘

Contenedor CLFS legítimo:
  [Header 0x100 bytes][Record: cbRecord bytes de datos reales]

Contenedor malformado (evil.blf):
  [Header válido][cbRecord=0xFF00 → kernel lee 65,280 bytes]
                          ↓
  Kernel overflow → llega a CClfsContainerContext falso
                          ↓
  pContainer  = TargetKernelAddress - 0x10
  cbContainer = ValueToWrite
                          ↓
  Driver usa estructura falsa → escribe ValueToWrite en TargetKernelAddress

주요 함수 — CVE-2025-60709.c

함수용도
GetKernelBase()ZwQuerySystemInformation(SystemModuleInformation) → ntoskrnl.exe 베이스
KillETW()VirtualProtect + ntdll.dll의 EtwEventWrite를 0xC3(RET)으로 덮어씀
KillAMSI()amsi.dll 로드 + AmsiScanBuffer를 0xC3(RET)으로 덮어씀
GroomLookaside()lookaside 리스트 고갈을 위해 4096개의 CLFS 로그 생성 → 결정론적 힙
ClfsArbWrite()익스플로잇의 핵심 — 커널 임의 쓰기 프리미티브
main()공격 조율: ETW→AMSI→groom→토큰 탈취→임의 쓰기→beacon

C와 Go의 차이점

측면C 버전Go 버전
유형기능하는 익스플로잇(문서 기준)교육용 데모 전용
API직접 접근(ntdll, clfsw32, advapi32)syscall.NewLazyDLL() 래퍼
CLFS 체크섬전체 알고리즘단순화된 플레이스홀더
커널 주소실제 주소하드코딩 플레이스홀더(0x123456)
C2 페이로드1789바이트 셸코드테스트용 NOP 바이트(0x90)
예상 결과SYSTEM으로 권한 상승"Arb write failed (yeah)" 메시지

컴파일

C 버전 (Visual Studio Build Tools + Windows SDK 필요):

cl /O1 /MT /link ntdll.lib advapi32.lib clfsw32.lib CVE-2025-60709.c

Go 버전 (Windows x64에서 Go 1.19+ 필요):

go build -ldflags="-s -w" -o CVE-2025-60709.exe CVE-2025-60709.go

🛡️ 완화 및 탐지

Windows 완화

완화효과
HVCI(Hypervisor-protected Code Integrity)높음 — 커널 메모리 쓰기 방지
kCFI(Kernel Control Flow Integrity)높음 — ROP/JOP 체인 방해
CFG(Control Flow Guard)중간 — 셸코드 실행 방해
Windows Defender중간 — 알려진 기법 탐지
Windows 업데이트높음 — 공식 패치가 취약점을 제거

YARA 규칙

rule CVE_2025_60709_CLFS_LPE {
    meta:
        description = "Detects CVE-2025-60709 CLFS LPE exploit"
        author      = "KONDORDEVSECURITYCORP"
        date        = "2026-03"
        cve         = "CVE-2025-60709"
        severity    = "critical"

    strings:
        $clfs_sig   = { 01 02 00 00 }
        $magic      = { 37 13 37 13 }
        $evil_file  = "evil.blf" ascii wide
        $groom_file = "groom_" ascii wide
        $etw_func   = "EtwEventWrite" ascii wide
        $amsi_func  = "AmsiScanBuffer" ascii wide
        $token_off  = { C0 04 00 00 }       // EPROCESS_TOKEN = 0x4C0

    condition:
        3 of them
}

IOCs — 시스템 아티팩트

유형값
변조된 파일C:\Windows\Temp\evil.blf
변조된 로그\\.\C:\Windows\Temp\evil_log
그루밍 파일C:\Windows\Temp\groom_00000.blf … groom_04095.blf
프로세스비정상적인 높은 우선순위(REALTIME_PRIORITY_CLASS)

행동 기반 탐지

도구 다운로드