[ << ALL_FEED ]

How to CVE-2025-54916? Low-effort vulnerability research

More in Windows

How to CVE-2025-54916? Low-effort vulnerability research 💻

Hi, ESC-VR here.

The Telegram post format is rarely suitable for analyzing complex vulnerabilities, but the bug we found in the depths of NTFS, fixed in the September patch, could be found in a rather unusual way (and we managed to fit the story into a post).

If you are interested in vulnerability analysis, you have probably heard of CodeQL, SonarQube, Snyk, Semgrep — classic SAST systems. Their common drawback: most often you need full access to the source code. When that is not available, the value of such tools quickly drops to zero, and the complexity of queries makes them difficult to apply to decompiled listings or code fragments.

You need something simple, with an understandable query language and no requirement for a full codebase. Such a solution exists — it is weggli-rs: an interactive, console utility for performing semantic search. It is suitable for searching through decompiled listings and partial codebases.

What do we mean by “partial codebases”? For example, the leaked Windows XP SP1 source code, leaked in 2020. Despite its age, it is an invaluable source of knowledge about the internals of modern Windows.

🎯 Our goal: find classic stack overflows via memcpy/memmove calls. We are looking for a function where:

• a buffer is declared on the stack;
• there is a call to memcpy/memmove;
• the address of this stack buffer is passed as the first argument.

This is enough to gather many candidates for stack buffer overflow (not all, but many). The query for weggli:

weggli -R "$func=RtlCopyMemory|memmove|memcpy" "_ $v; $func(&$v,_,_)"

Next, you need to narrow down the selection. For example, require that the size of the copied buffer is specified by an expression involving subtraction. This highlights places at risk of integer underflow:

weggli.exe -R "$func=RtlCopyMemory|memmove|memcpy" "_ $v; $func(&$v,_,_(_-_))"

The vulnerability fixed in September could be highlighted with this query:

weggli -R "$func=RtlCopyMemory|memmove|memcpy" "_ $v; $func(&$v,_,_($a->$b))

In this pattern, we are looking for all functions where:

• a buffer is declared on the stack;
• there is a call to memcpy/memmove;
• the address of this stack buffer is passed as the first argument;
• the size of the copied buffer is determined by a field of some structure.

In conclusion, we encourage you to try using weggli-rs and find the fixed vulnerability in the Windows XP SP1 source code.

HINT: it seems you should look in base/fs, and the name of the vulnerable function had something to do with writing to a log or somewhere else 😏

And if you want to learn how to trigger this vulnerability, check out our previous research, published on the PT SWARM blog.

#escvr #cve #win
@ptescalator

More from author_vr

More from author_vr

More in Windows