SteelSeries Nahimic 3 1.10.7 allows Directory traversal.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a Windows C++ proof-of-concept exploit for CVE-2025-68921 (Nahimic local privilege escalation). It is a Visual Studio project that builds a console application. Structure & key files: - CVE-2025-68921/PoC.cpp: Main exploit logic. Orchestrates a filesystem race using opportunistic locks (oplocks), directory change notifications, reparse-point tricks (junctions), and DOS device symlinks in the Object Manager namespace. It triggers Windows Installer activity by dropping and installing an embedded MSI, then watches C:\Config.msi for creation of a .rbs rollback script and overwrites it with an embedded attacker-controlled cmd.rbs. - CVE-2025-68921/FileOpLock.{h,cpp}: Helper class to request an oplock via FSCTL_REQUEST_OPLOCK and invoke a callback when the oplock breaks, enabling precise race timing. - CVE-2025-68921/def.h: NT/native structure and function typedefs used for low-level file/object operations (reparse buffers, NtCreateFile/NtSetInformationFile, etc.). - CVE-2025-68921/resource.{h,rc}: Embeds two resources: cmd.rbs (rollback script payload) and Msi_Rollback.msi (used to trigger rollback script creation/execution). - README.md: Describes the vulnerability as Nahimic LPE to NT AUTHORITY\\SYSTEM, references Lenovo tracking (LEN-18785), NVD entry, video, and write-up. Exploit capabilities (high level): - Local privilege escalation by coercing a privileged installer/rollback process to execute attacker-controlled rollback script content. - Uses oplock-based race to win timing against privileged file operations. - Uses filesystem redirection primitives (junction + DOS device symlink under GLOBALROOT\\RPC Control) to steer operations toward attacker-controlled paths. - Overwrites the generated rollback .rbs file in C:\Config.msi with embedded payload content. No network IOCs are present; the exploit is purely local and interacts with Windows filesystem paths and the Windows Installer API (MsiInstallProduct).
Repository contains a Windows local exploit PoC implemented as a Visual Studio C++ project (stdcpp20) targeting CVE-2025-68921. Core code is in CVE-2025-68921/PoC.cpp with an auxiliary oplock helper (FileOpLock.cpp/.h) and NT/reparse definitions (def.h). The exploit uses NTFS opportunistic locks (FSCTL_REQUEST_OPLOCK) plus directory change notifications (ReadDirectoryChangesW) to win a timing window around Windows Installer rollback file creation under C:\Config.msi. It manipulates filesystem objects and NT object manager paths (GLOBALROOT\RPC Control) via DOS device/NT symlinks and junction/reparse-point style primitives (functions like CreateJunction/DosDeviceSymLink are referenced; part of PoC.cpp is truncated but intent is clear). Once an .rbs rollback script is observed, it relaxes DACLs on the directory handle and overwrites the rollback script with an embedded resource (cmd.rbs). It also drops and installs/uninstalls an embedded MSI (Msi_Rollback.msi) from C:\Windows\Temp to trigger rollback behavior. Overall purpose: achieve a privileged file write / rollback script hijack leading to local privilege escalation. README.md appears to be misleading marketing text unrelated to exploit operation; actual functionality is the C++ PoC.
This repository contains a working proof-of-concept (PoC) exploit for CVE-2025-68921, a local privilege escalation vulnerability in the Nahimic audio software (commonly pre-installed on Lenovo and other gaming laptops). The exploit is implemented in C++ and consists of a Visual Studio project with source files for the main exploit logic (PoC.cpp), file operation locking (FileOpLock.cpp/h), and supporting definitions (def.h, resource.h, resource.rc). The exploit abuses a race condition and insecure file operations in the handling of rollback scripts by the Nahimic installer. It manipulates the C:\Config.msi directory, creates and deletes junctions and symbolic links, and leverages oplocks to win a race and overwrite a rollback script (.rbs file) with attacker-controlled content. This allows arbitrary code execution as SYSTEM when the rollback script is processed. Key fingerprintable endpoints include the C:\Config.msi directory, rollback script files within it, C:\ProgramData\Nahimic\render.txt, and the use of the GLOBAL\GLOBALROOT\RPC Control namespace for symbolic links. The exploit is local-only and requires the attacker to have code execution as a low-privileged user on a vulnerable system. The repository is well-structured, with clear separation of exploit logic, helper classes, and resources, and is intended for research and demonstration purposes.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.