在 System Informer 4.0.26241.138 版本之前,phsvc 辅助组件存在一个不正确的授权漏洞,允许本地攻击者通过从任何经过 Authenticode 签名的进程发起连接,来访问特权 API。攻击者可以将代码加载到由 Microsoft 签名的主机进程中(例如 rundll32.exe),然后连接到 SiSvcApiPort 端口,并调用 PhSvcApiCreateService 接口,从而以 SYSTEM 权限执行代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| winsiderss | System Informer | 0 ~ 4.0.26241.138 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet