Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2025-54110-Kernel-EoP-PoC — 项目日期:2025年10月 / 针对Windows `NtQueryDirectoryObject` 系统调用中CVE-2025-54110内核级整数溢出漏洞的PoC实现。 | Kitploit
工具/GitHubGitHub/canomer/cve-2025-54110-kernel-eop-poc
漏洞分析漏洞利用逆向工程论文与研究学习与教育二进制利用
GitHubcanomer/cve-2025-54110-kernel-eop-poc

CVE-2025-54110-Kernel-EoP-PoC

项目日期:2025年10月 / 针对Windows `NtQueryDirectoryObject` 系统调用中CVE-2025-54110内核级整数溢出漏洞的PoC实现。

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
查看仓库
111124个月前尚未审核
分享

CVE-2025-54110-Kernel-EoP-PoC

CVE-2025-54110 利用代码实现——Windows NtQueryDirectoryObject 系统调用中的内核级整数溢出漏洞。

CVE-2025-54110 - Windows 内核整数溢出分析

CVE: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-54110

本仓库包含针对 CVE-2025-54110 内核权限提升漏洞的仅崩溃 PoC,专为安全研究、逆向工程和利用开发研究而开发。该代码旨在演示漏洞研究技术,包括:

  • 使用 Ghidra 版本跟踪进行二进制差异对比
  • Windows 补丁星期二分析
  • 内核漏洞研究方法论
  • 结构化异常处理 (SEH) 行为分析

此 PoC 不会实现权限提升或可靠的蓝屏死机 (BSOD)。它设计用于安全触发访问违例,这些违例会被 Windows 内核保护机制捕获。


概述

CVE-2025-54110:Windows 内核权限提升漏洞

发布日期: 2025 年 9 月(Windows 星期二安全补丁)

属性值
CWECWE-190:整数溢出或回绕
CVSS 3.1 评分8.8(高)/ 7.7(临时)
向量字符串CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
攻击向量本地
攻击复杂度低
所需权限低
用户交互无
影响范围已变更
机密性影响高
完整性影响高
可用性影响高
利用成熟度未经验证

执行摘要

Windows 内核中的一个整数溢出漏洞允许经过身份验证的攻击者在本地提升权限。根据微软的安全公告:

"攻击者可以通过从沙盒用户模式进程发送特制的输入来利用此漏洞,触发整数溢出,导致内核中的缓冲区溢出,从而实现权限提升或沙盒逃逸。"

潜在影响

  • 成功的攻击者可能获得 SYSTEM 权限
  • 从用户模式受限进程中的沙盒逃逸
  • 内核内存损坏,导致代码执行

可利用性评估

  • 公开披露: 否
  • 在野利用: 否
  • 微软评估: 更可能被利用

研究方法

1. 补丁分析工作流```

Windows Update Files from Aug 2025 & Sep 2025 (KB.msu) ↓ Extract CAB Files ↓ Calculate SHA-256 Hashes (August vs September) ↓ Identify Changed Files ↓ Ghidra Version Tracking Analysis ↓ Setting Symbol Servers to Clarify Function Names ↓ Function-Level Diff Comparison

### 2. 已分析的文件

初步分析聚焦于两个主要的内核组件:

#### win32k.sys (-)
- **结果:** 未检测到显著变化
- **评分范围:** 0.97-1.0(高相似度)
- **结论:** 不是 CVE-2025-54110 的易受攻击组件

#### ntoskrnl.exe (+)
- **结果:** 多个函数发生了显著变化
- **评分范围:** 函数评分 ≤0.951
- **长度差异:** 检测到源与目标字节长度变化
- **导出的总项数:** 2,036 个函数用于分析

### 3. Ghidra 版本跟踪结果

在 `ntoskrnl.exe` 中识别出的变化示例:

| 评分 | 置信度 | 源长度 | 目标长度 | 源函数 | 目标函数 |
|-------|------------|---------------|-------------|-----------------|---------------|
| 0.951 | 2.618 | 1023 | 365 | FUN_1403146d0 | FUN_1403a4ea0 |
| 0.950 | 2.285 | 113 | 203 | FUN_140680810 | FUN_1406d952c |
| 0.950 | 3.137 | 782 | 1050 | FUN_14032106c | FUN_140303a38 |
| 0.951 | 2.675 | 141 | 171 | FUN_140407bd0 | FUN_140a172a0 |
| 0.951 | 2.660 | 346 | 150 | FUN_140610e60 | FUN_1406115d4 |

---

## PoC 声明

### 技术方法

该 PoC(`precise_overflow_bsod.c`)试图通过以下方式触发整数溢出漏洞:

1. **精确阈值计算:** `0xfffffdbc`(源自 base=0x20, name=0x200)
2. **NtQueryDirectoryObject API:** 用于触发溢出的目标函数
3. **多阶段攻击策略:**
   - 阶段 1:精确整数溢出尝试
   - 阶段 2:内核内存定位
   - 阶段 3:多线程利用

### 代码结构```c
// Key threshold values calculated for overflow
ULONG precise_thresholds[] = {
    0xfffffdbc,  // Precise threshold - base=0x20, name=0x200
    0xfffffdbb,  // Threshold - 1
    0xfffffdbd,  // Threshold + 1
    0xfffffdba,  // Threshold - 2  
    0xfffffdbe,  // Threshold + 2
};

// Buffer configurations to test edge cases
PVOID buffer_types[] = {
    VirtualAlloc(NULL, 0x1000, MEM_COMMIT, PAGE_READWRITE),  // Normal buffer
    VirtualAlloc(NULL, 0x10, MEM_COMMIT, PAGE_READWRITE),    // Small buffer
    NULL,                                                    // NULL pointer
    (PVOID)0x4141414141414141,                              // Invalid pointer
    (PVOID)0x0000000000000000,                              // Zero address
};

已测试的利用向量```

NtQueryDirectoryObject() Parameters: ├── DirectoryHandle: \BaseNamedObjects, \KernelObjects, etc. ├── Buffer: Various pointer configurations ├── BufferLength: Calculated overflow thresholds (0xfffffdbc variants) ├── ReturnSingleEntry: TRUE/FALSE variations ├── RestartScan: TRUE/FALSE variations └── Context: Controlled iteration state

---

## 为什么该PoC不会导致系统崩溃

### 实际结果

该PoC一致返回 `STATUS_ACCESS_VIOLATION (0xC0000005)`,而不会导致蓝屏死机(BSOD)。这是**设计使然**,并展示了多个关键的Windows内核安全机制:

### 1. 结构化异常处理(SEH)```
User-Mode Input → NtQueryDirectoryObject
                        ↓
                  ProbeForRead/Write
                        ↓
                  __try { ... }
                        ↓
              Access Violation Detected
                        ↓
                  __except { ... }
                        ↓
            Return STATUS_ACCESS_VIOLATION

工作原理:

  • Windows内核系统调用将用户模式指针访问包装在异常处理程序中
  • 无效的内存访问会被捕获,而不是允许传播
  • 系统向调用者返回错误代码而不是崩溃

2. SMAP(监督模式访问阻止)

现代CPU功能,防止内核模式(Ring 0)在未经明确授权的情况下访问用户模式(Ring 3)内存:``` Kernel attempts to access user pointer ↓ SMAP checks permission (STAC/CLAC instructions) ↓ Unauthorized access detected ↓ CPU generates #PF (Page Fault) ↓ Caught by kernel exception handler

**Impact on PoC:**
- 即使发生溢出,内核到用户内存的直接访问也会被阻止
- 防止利用指针解引用漏洞

### 3. KASLR(内核地址空间布局随机化)```
Boot Time: Kernel Base = Random Address
                ↓
Hardcoded PoC address (0xfffffdbc)
                ↓
        Does NOT match actual kernel structures
                ↓
    Write to non-critical memory OR caught by SEH

为什么BSOD不会发生:

  • PoC使用静态地址/阈值
  • 真实内核结构位于随机化地址
  • 写入操作错过关键目标(例如EPROCESS、Pool Headers)

4. 内核池完整性检查

Windows 10+ 实现了增强的池损坏检测:``` Heap/Pool Allocation ↓ Header Contains: ├── Magic Values ├── Size Information └── Checksums ↓ On Free/Access: Validate Integrity ↓ Corruption Detected? ↓ [YES] → Safe Exception → Return Error [NO] → Proceed Normally

---

## 概念验证执行输出分析

### 预期输出

看到 `STATUS_ACCESS_VIOLATION (0xC0000005)`,然后就是正常的。```
C:\Users\reLab\Desktop\cve>.\poc64.exe
==================================================
    CVE-2025-54110 - Kernel Integer Overflow PoC
==================================================
[!] WARNING: This code may crash the system (BSOD).
[?] Do you want to continue? (y/n): y

[>] Targeting directory: \BaseNamedObjects
[*] Attempting precision integer overflow...
[+] Corruption detected with threshold: 0xFFFFFDBC (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBB (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBD (Status: 0xC0000005)
[!] Vulnerability triggered. Attempting to crash system via race condition...

[>] Targeting directory: \KernelObjects
[*] Attempting precision integer overflow...
[+] Corruption detected with threshold: 0xFFFFFDBC (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBB (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBD (Status: 0xC0000005)
[!] Vulnerability triggered. Attempting to crash system via race condition...

[>] Targeting directory: \Sessions
[*] Attempting precision integer overflow...
[+] Corruption detected with threshold: 0xFFFFFDBC (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBB (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBD (Status: 0xC0000005)
[!] Vulnerability triggered. Attempting to crash system via race condition...

[>] Targeting directory: \Windows
[*] Attempting precision integer overflow...
[+] Corruption detected with threshold: 0xFFFFFDBC (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBB (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBD (Status: 0xC0000005)
[!] Vulnerability triggered. Attempting to crash system via race condition...

[-] Exploit finished. If the system is still running, the attack may have been mitigated.

C:\Users\reLab\Desktop\cve>
image

Verbossed Experiment```

C:\Users\reLab\Desktop\cve>.\poc64_verbose11.exe

CVE-2025-54110 PRECISION INTEGER OVERFLOW BSOD EXPLOIT Threshold: 0xfffffdbc (base=0x20, name=0x200) !!! WARNING: HIGH PROBABILITY OF SYSTEM CRASH !!!

[+] Current user: desktop-lfkkhu2\relab [+] Current PID: 1444

[!] THIS EXPLOIT HAS HIGH CHANCE OF CAUSING BSOD! [!] Continue? (y/n): y [+] NT functions initialized successfully [+] Using precise threshold: 0xfffffdbc

下载工具