关键信息 漏洞名称: Agnium Outpost Security Suite 8.1 - Local Privilege Escalation EDB-ID: 27282 CVE: NO-CVE 作者: Ahmad Moghiml 类型: LOCAL 平台: WINDOWS 日期: 2013-08-02 验证状态: EDB Verified 漏洞应用: Agnium Outpost Security Suite 8.1 漏洞描述 漏洞标题: Agnium Outpost security suite privilege escalation - 0Day 发布日期: 2013-08-02 漏洞作者: Ahmad Moghiml (http://mallocat.com/, https://twitter.com/mall@cat) 厂商主页: http://www.agnitum.com/ 软件链接: http://dl2.agnitum.com/OutpostSecuritySuiteProInstall.exe 版本: 8.1 Latest build 测试平台: windows CVE编号: NO-CVE 参考链接 Reference: http://mallocat.com/a-journey-to-antivirus-escalation/ Demo: http://mallocat.com/wp-content/uploads/2013/08/win7.swf Exploit code: http://mallocat.com/wp-content/uploads/2013/08/escalate.7z Exploit code: https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/27282.7z 利用步骤 从低权限账户执行以下步骤: 1. 注册 Regsvr32.exe /s C:\Program Files\agnitum\Outpost Security Suite Pro\..\..\x.dll 2. 运行 exploit.exe