生成武器化 JPEG 文件,利用 CVE-2025-50165(Windows 图形组件远程代码执行漏洞)结合自定义 x64 shellcode、堆喷射、ROP 链以及 AV/EDR 规避技术,用于授权渗透测试。
通过恶意 JPEG 触发的严重远程代码执行 – Windows 11 24H2(未修补)
CVSS 9.8 – 无需任何权限,也无需用户交互
CVE-2025-50165 - windowscodecs.dll untrusted pointer dereference
Discovered by Zscaler ThreatLabz
Patched: November 2025 (KB5040442)
poc/ → Final weaponized JPEGs
scripts/generate_poc.py → Main generator (Encrypter15)
shellcode/calc_x64.bin → Raw shellcode for analysis
README.md → This file
pip install Pillow
python scripts/generate_poc.py
→ 生成 poc/CVE-2025-50165_x64_encrypter15.jpg
使用 Photos、Office、Edge 预览等打开该 JPEG → calc.exe 会在易受攻击的系统上立即启动。
仅限已获授权的安全测试与研究。未经明确许可,不得针对任何系统使用本工具。
Encrypter15 – [email protected]
保持警惕。