Exploitation Summary
EIP tracks 1 public exploit for CVE-2025-29969. PoCs published by SafeBreach-Labs.
AI-analyzed exploit summary This repository contains functional exploit code for CVE-2025-29969, a Time-of-check time-of-use (TOCTOU) vulnerability in the MS-EVEN protocol. The exploit allows low-privileged users to write arbitrary files to a remote machine via SMB, bypassing administrative privileges. The repository includes two scripts: one for remote file existence checks and another for weaponizing the vulnerability to upload files.
Description
Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network.
Exploits (1)
This repository contains functional exploit code for CVE-2025-29969, a Time-of-check time-of-use (TOCTOU) vulnerability in the MS-EVEN protocol. The exploit allows low-privileged users to write arbitrary files to a remote machine via SMB, bypassing administrative privileges. The repository includes two scripts: one for remote file existence checks and another for weaponizing the vulnerability to upload files.
References (1)
Scores
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H