Friday, October 2, 2026

PoC Exploit Unveiled for Windows Disk Cleanup Elevation Vulnerability

Microsoft addressed a high-severity elevation of privilege vulnerability (CVE-2025-21420) in its Windows Disk Cleanup Utility (cleanmgr.exe) during February 2025’s Patch Tuesday.

The flaw, scoring 7.8 on the CVSS scale, enabled attackers to execute malicious code with SYSTEM privileges through DLL sideloading and a directory traversal technique.

Technical Analysis of CVE-2025-21420

The vulnerability stems from cleanmgr.exeโ€™s failure to validate DLL loading paths and mitigate symbolic link attacks.

Key components include:

1. Exploitation Mechanism

  • DLL Sideloading: Attackers plant malicious libraries (e.g., dokannp1.dll) in writable system directories. bashcp .\dokan1.dll C:\Users\<username>\System32\System32\System32\dokannp1.dll cleanmgr /sageset:2 This command chain exploits path interception vulnerabilities to load unsigned DLLs.
  • SilentCleanup Task Hijacking: The Windows Task Schedulerโ€™s SilentCleanup task (running as SYSTEM) deletes folder contents without proper symlink checks. Attackers abuse this via: python# Exploit script structure os.makedirs(r'C:\$Windows.~WS') os.makedirs(r'C:\ESD\Windows') open(r'C:\ESD\Windows\dummy.txt', 'w').close() By redirecting folder deletions to C:\Config.Msi, attackers trigger arbitrary file operations.

2. Vulnerability Chain

Pre-Patch BehaviorPost-Patch Mitigation
No Redirection Guard for symlinksSetProcessMitigationPolicy enabled
Untrusted DLL loading from user pathsStrict signature validation for DLLs
Privileged file deletion via junctionsCWE-59 resolved via path normalization

Proof-of-Concept (PoC) Workflow

Security researchers demonstrated exploitation using a multi-stage process:

  1. Folder Setup: Create nested directories (C:\ESD\Windows) with dummy files to trigger SilentCleanupโ€™s deletion routine.
  2. Junction Redirection: Use FolderContentsDeleteToFolderDelete to convert C:\ESD\Windows into a junction pointing to C:\Config.Msi.
  3. Privilege Escalation: Execute osk.exe post-cleanup to spawn a SYSTEM shell via the compromised Config.Msi directory.
python# Sample exploit script (abridged)
import os, time
os.makedirs(r'C:\$Windows.~WS', exist_ok=True)
os.makedirs(r'C:\ESD\Windows', exist_ok=True)
with open(r'C:\ESD\Windows\dummy.txt', 'w') as f: f.write('trigger')
input("Press Enter after setting up junctions...")
os.startfile(r'C:\Windows\System32\cleanmgr.exe')

Mitigation and Patch Deployment

Microsoftโ€™s February 2025 update resolves the flaw through:

  • Redirection Guard: Blocks symlink attacks via PROCESS_MITIGATION_REDIRECTION_TRUST_POLICY.
  • DLL Signature Enforcement: cleanmgr.exe now validates digital signatures before loading libraries.

Recommended Actions:

  • Apply KB5025321 via Windows Update/WSUS immediately.
  • Audit system directories for unauthorized DLLs (e.g., dokannp1.dll).
  • Monitor cleanmgr.exe executions in non-standard contexts.

This patch is part of a broader update fixing 67 vulnerabilities, including actively exploited zero-days in Windows Ancillary Function Driver (CVE-2025-21418) and NTLM (CVE-2025-21377).

Organizations should prioritize patch deployment given the exploitโ€™s low complexity and high impact.

Find this News Interesting! Follow us on Google News, LinkedIn, & X to Get Instant Updates

Anupriya
Anupriya
Any Priya is a cybersecurity reporter at GBHackers On Security, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Todayโ€™s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories:ย identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

16-Year-Old Suspected KillSec Ransomware Leader Arrested in International Operation

International law enforcement authorities have arrested three suspects linked...

FTC Investigates OpenAI and Anthropic Over Consumer Risks From Advanced AI Models

The U.S. Federal Trade Commission (FTC) has initiated a...

New Infostealer Can Steal Passwords, Cards, Cookies and Wi-Fi Keys From Windows PCs

A Python-based infostealer builder that enables threat actors to...

Fortinet FortiMail Path Traversal Flaw Actively Exploited to Compromise Servers

Fortinet has disclosed a critical vulnerability in FortiMail that...

Apache HTTP Server Flaws Enable Remote Code Execution and Denial-of-Service Attacks

Apache HTTP Server administrators are urged to apply security...

U.S. Arrests Company Owner Accused of Shipping $300 Million in Restricted GPU Servers to China

U.S. authorities have arrested Greg Lui, a 38-year-old California-based...

Related Articles

Recent News