CVE-2026-24294:Windows SMB 本地 NTLM 反射权限提升 PoC
github.com | 漏洞 | 高危 | CVE-2026-24294 | #public-poc | #featured | #privilege-escalation | #windows | #windows-server | #smb | #ntlm | #ntlm-reflection | #lpe | #poc | #petitpotam | #cve-2026-24294
摘要
该公开 PoC 针对 Windows Server 2025 的默认配置。它将任意端口上的 SMB 连接与会话多路复用相结合,将被迫提交的特权 NTLM 认证反射回本地 SMB 服务,从而使本地低权限用户能够获得 NT AUTHORITY\SYSTEM 权限。Microsoft 将这一根本问题归类为 Windows SMB Server 中的身份验证不当,进而导致本地权限提升,多个 Windows 10、Windows 11 和 Windows Server 版本受到影响。
为什么值得关注
官方 CVSS 3.1 向量表明该漏洞需要本地低权限访问,但攻击复杂度低、无需用户交互,成功后可造成完整的机密性、完整性和可用性影响。应安装适用于各 Windows 版本的最新 Microsoft 安全更新;同时启用并强制 SMB 签名、限制 NTLM、监控异常的本地 SMB 中继活动。公开信息目前只确认 PoC,不应标记为在野利用。
- 厂商
- Microsoft
- 产品
- Windows SMB Server
- 受影响版本
- Multiple supported Windows 10, Windows 11, and Windows Server releases; this PoC specifically targets Windows Server 2025 default configuration
- CVSS
- 7.8
- 发布时间
- 收录时间
Skip to content