Rapid7 Velociraptor是美国Rapid7公司的一个数字取证与事件响应平台。 Rapid7 Velociraptor 0.76.6之前版本存在注入漏洞,该漏洞源于Windows.Collectors.Remapping工件中的YAML注入,主机名字段通过Go的text/template插入YAML模板时未转义,可能导致攻击者利用特制的collection ZIP注入新的挂载重映射条目,当分析师应用生成的remapping文件时,任意VQL代码在分析师机器上以NullACLManager权限执
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Rapid7 | Velociraptor | < 0.76.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Rapid7 | Velociraptor | 0 ~ 0.76.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet