
보안 연구용 Windows CLFS LPE 익스플로잇 PoC
🚨 EXPLOIT PoC — 보안 연구, 취약점 분석 및 방어 목적으로만 사용하십시오
🚨 EXPLOIT PoC — 보안 연구, 취약점 분석 및 방어 목적으로만 제공됩니다
CVE-2025-60709은 Windows CLFS.sys(Common Log File System) 드라이버의 로컬 권한 상승(LPE) 취약점입니다. 로컬 코드 실행 권한이 있는 공격자는 CLFS 컨테이너 파싱의 버퍼 오버플로를 통해 일반 사용자에서 NT AUTHORITY\SYSTEM으로 권한을 상승시킬 수 있으며, 커널 메모리에 대한 임의 쓰기 프리미티브를 획득할 수 있습니다.
이 저장소에는 두 가지 구현이 포함되어 있습니다:
| 필드 | 세부 정보 |
|---|---|
| CVE ID | CVE-2025-60709 |
| 유형 | 로컬 권한 상승(LPE) |
| 구성 요소 | CLFS.sys(Common Log File System 드라이버) |
| 대상 시스템 | Windows 11 24H2(빌드 26100.3485+) |
| 아키텍처 | x64 전용 |
| 공격 벡터 | CLFS 컨테이너 파싱의 버퍼 오버플로 |
| 영향 | NT AUTHORITY\SYSTEM으로 권한 상승 |
| 전제 조건 | 로컬 코드 실행(일반 사용자) |
CVE-2025-60709/
├── CVE-2025-60709.c (5.3 KB, 157 líneas) — Exploit C original
├── CVE-2025-60709.go (9.2 KB, 285 líneas) — Port Go (demo educativa)
└── README.txt (4.2 KB, 132 líneas) — Documentación original
┌─────────────────────────────────────────────────────────────┐
│ CVE-2025-60709 LPE │
└─────────────────────────────────────────────────────────────┘
[1] EVASIÓN DE DEFENSAS
├─ KillETW() → Parchea EtwEventWrite en ntdll con RET (0xC3)
└─ KillAMSI() → Parchea AmsiScanBuffer en amsi.dll con RET (0xC3)
[2] HEAP GROOMING (preparación de memoria)
└─ GroomLookaside()
├─ Crea 4096 archivos: C:\Windows\Temp\groom_00000.blf
├─ Llama CreateLogFile() + AddLogContainer() por cada uno
└─ Agota lookaside lists → garantiza layout de heap predecible
[3] PRIMITIVA DE ESCRITURA ARBITRARIA — ClfsArbWrite(Address, Value)
├─ Construye buffer CLFS malformado (0x102010 bytes)
│ ├─ Firma válida CLFS en +0x00: 0x0201
│ ├─ Sector size shift en +0x14: 2
│ ├─ First client region en +0x28: 0x100
│ ├─ cbRecord OVERSIZED en +0x100: 0xFF00 (64 KB > datos reales)
│ ├─ Marcador shadow zone en +0x9A8: 0x13371337
│ └─ CClfsContainerContext falso en offset (0xFF00 + 0x100):
│ ├─ pContainer = TargetAddress - 0x10
│ └─ cbContainer = Value (dato a escribir)
├─ Calcula checksum CLFS correcto (driver lo valida)
├─ Escribe contenedor malformado → C:\Windows\Temp\evil.blf
├─ Crea log apuntando a evil.blf
├─ Llama ClfsReadRestartArea() → dispara parsing kernel
└─ Driver desborda buffer → escribe Value en Address ✓
[4] ROBO DE TOKEN SYSTEM
├─ Lee EPROCESS del proceso SYSTEM via PsInitialSystemProcess
└─ Extrae token en EPROCESS + EPROCESS_TOKEN (offset 0x4c0)
[5] ESCALACIÓN DE PRIVILEGIOS
└─ ClfsArbWrite(CurrentEprocess + 0x4c0, SystemToken)
└─ Sobreescribe token del proceso actual con token SYSTEM ✓
[6] EJECUCIÓN DE PAYLOAD C2
├─ VirtualAlloc(PAGE_EXECUTE_READWRITE)
├─ Copia shellcode beacon de 1789 bytes
├─ CreateThread() → ejecución como NT AUTHORITY\SYSTEM
└─ Beacon C2: IPv6 + DoH → fallback Gmail drafts
└─ sRDI + sleep obfuscation + ETW/AMSI ya parcheados
[7] PERSISTENCIA
└─ Sleep(INFINITE) → proceso mantiene token SYSTEM
| 필드 | 오프셋 | 설명 |
|---|---|---|
EPROCESS_TOKEN | 0x4C0 | 프로세스 보안 토큰 |
EPROCESS_PID | 0x440 | 프로세스 ID(PID) |
EPROCESS_LINKS | 0x448 | 활성 프로세스 연결 리스트 |
EPROCESS_NAME | 0x5A8 | 프로세스 이름(ImageFileName) |
⚠️ 이 오프셋은 Windows 빌드마다 다릅니다. 다른 버전에서는 업데이트가 필요합니다.
Contenedor CLFS legítimo:
[Header 0x100 bytes][Record: cbRecord bytes de datos reales]
Contenedor malformado (evil.blf):
[Header válido][cbRecord=0xFF00 → kernel lee 65,280 bytes]
↓
Kernel overflow → llega a CClfsContainerContext falso
↓
pContainer = TargetKernelAddress - 0x10
cbContainer = ValueToWrite
↓
Driver usa estructura falsa → escribe ValueToWrite en TargetKernelAddress
CVE-2025-60709.c| 함수 | 용도 |
|---|---|
GetKernelBase() | ZwQuerySystemInformation(SystemModuleInformation) → ntoskrnl.exe 베이스 |
KillETW() | VirtualProtect + ntdll.dll의 EtwEventWrite를 0xC3(RET)으로 덮어씀 |
KillAMSI() | amsi.dll 로드 + AmsiScanBuffer를 0xC3(RET)으로 덮어씀 |
GroomLookaside() | lookaside 리스트 고갈을 위해 4096개의 CLFS 로그 생성 → 결정론적 힙 |
ClfsArbWrite() | 익스플로잇의 핵심 — 커널 임의 쓰기 프리미티브 |
main() | 공격 조율: ETW→AMSI→groom→토큰 탈취→임의 쓰기→beacon |
| 측면 | C 버전 | Go 버전 |
|---|---|---|
| 유형 | 기능하는 익스플로잇(문서 기준) | 교육용 데모 전용 |
| API | 직접 접근(ntdll, clfsw32, advapi32) | syscall.NewLazyDLL() 래퍼 |
| CLFS 체크섬 | 전체 알고리즘 | 단순화된 플레이스홀더 |
| 커널 주소 | 실제 주소 | 하드코딩 플레이스홀더(0x123456) |
| C2 페이로드 | 1789바이트 셸코드 | 테스트용 NOP 바이트(0x90) |
| 예상 결과 | SYSTEM으로 권한 상승 | "Arb write failed (yeah)" 메시지 |
C 버전 (Visual Studio Build Tools + Windows SDK 필요):
cl /O1 /MT /link ntdll.lib advapi32.lib clfsw32.lib CVE-2025-60709.c
Go 버전 (Windows x64에서 Go 1.19+ 필요):
go build -ldflags="-s -w" -o CVE-2025-60709.exe CVE-2025-60709.go
| 완화 | 효과 |
|---|---|
| HVCI(Hypervisor-protected Code Integrity) | 높음 — 커널 메모리 쓰기 방지 |
| kCFI(Kernel Control Flow Integrity) | 높음 — ROP/JOP 체인 방해 |
| CFG(Control Flow Guard) | 중간 — 셸코드 실행 방해 |
| Windows Defender | 중간 — 알려진 기법 탐지 |
| Windows 업데이트 | 높음 — 공식 패치가 취약점을 제거 |
rule CVE_2025_60709_CLFS_LPE {
meta:
description = "Detects CVE-2025-60709 CLFS LPE exploit"
author = "KONDORDEVSECURITYCORP"
date = "2026-03"
cve = "CVE-2025-60709"
severity = "critical"
strings:
$clfs_sig = { 01 02 00 00 }
$magic = { 37 13 37 13 }
$evil_file = "evil.blf" ascii wide
$groom_file = "groom_" ascii wide
$etw_func = "EtwEventWrite" ascii wide
$amsi_func = "AmsiScanBuffer" ascii wide
$token_off = { C0 04 00 00 } // EPROCESS_TOKEN = 0x4C0
condition:
3 of them
}
| 유형 | 값 |
|---|---|
| 변조된 파일 | C:\Windows\Temp\evil.blf |
| 변조된 로그 | \\.\C:\Windows\Temp\evil_log |
| 그루밍 파일 | C:\Windows\Temp\groom_00000.blf … groom_04095.blf |
| 프로세스 | 비정상적인 높은 우선순위(REALTIME_PRIORITY_CLASS) |