关键信息 漏洞名称: Deep Instinct Windows Agent 1.2.29.0 - 'DeepMgmtService' Unquoted Service Path Edb-ID: 48174 CVE: N/A 作者: Oscar Flores 类型: LOCAL 平台: WINDOWS 日期: 2020-03-06 漏洞应用: Deep Instinct Management Service 漏洞类型: Unquoted Service Path 测试操作系统: Windows 10 Pro 64 bits 测试版本: 1.2.29.0 漏洞详情 漏洞发现者: Oscar Flores 发现日期: 2020-03-05 厂商主页: https://www.deepinstinct.com/ 软件链接: - https://www.deepinstinct.com/2019/05/22/hp-collaborates-with-deep-instinct-to-roll-out-ai-powered-malware-protection-for-next-generation-hp-elitebook-and-zbook-pcs/ - https://press.ext.hp.com/us/en/press-releases/2019/hp-elevates-premium-and-personalized-pc-experiences-for-leaders-and-creators.html 漏洞利用步骤 1. 发现Unquoted Service Path - SERVICE_START_NAME: LocalSystem - BINARY_PATH_NAME: C:\Program Files\HP Sure Sense\DeepMgmtService.exe 2. 利用方法 - 成功的尝试需要本地用户能够在系统根路径中未被检测到的位置插入代码,这些位置可能在应用程序启动或重启时执行。 - 如果成功,本地用户的代码将以应用程序的高权限执行。