Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-23968 PoC — Ilex International Sign&go Workstation Security Suite 后置链接漏洞

Source
Associated Vulnerability
Title:Ilex International Sign&go Workstation Security Suite 后置链接漏洞 (CVE-2020-23968)
Description:Ilex International Sign&go Workstation Security Suite是法国Ilex International公司的一个应用于单点登录环境的软件。 Ilex International Sign&go Workstation Security Suite 7.1版本存在安全漏洞,该漏洞源于允许通过符号链接攻击ProgramDataIlexS&GLogs00-sngWSService1.log权限提升。
Description
CVE-2020-23968
Readme
# CVE-2020-23968

Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on C:\ProgramData\Ilex\S&G\Logs\000-sngWSService1.log
File Snapshot

[4.0K] /data/pocs/2d4755d8c5608411e2bd77b229e9c60904dc9ba1 ├── [4.0K] ILEX-Exploit-C++ │   ├── [4.0K] CommonUtils │   │   ├── [3.7K] CommonUtils.cpp │   │   ├── [1.0K] CommonUtils.h │   │   ├── [1.1K] CommonUtils.sln │   │   ├── [4.8K] CommonUtils.vcxproj │   │   ├── [2.7K] CommonUtils.vcxproj.filters │   │   ├── [ 168] CommonUtils.vcxproj.user │   │   ├── [2.0K] DirectoryObject.cpp │   │   ├── [4.5K] FileOpLock.cpp │   │   ├── [ 789] FileOpLock.h │   │   ├── [5.0K] FileSymlink.cpp │   │   ├── [ 588] FileSymlink.h │   │   ├── [1.6K] Hardlink.cpp │   │   ├── [2.0K] NativeSymlink.cpp │   │   ├── [2.2K] ntimports.h │   │   ├── [5.2K] RegistrySymlink.cpp │   │   ├── [ 13K] ReparsePoint.cpp │   │   ├── [1.2K] ReparsePoint.h │   │   ├── [1.8K] ScopedHandle.cpp │   │   ├── [ 498] ScopedHandle.h │   │   ├── [ 298] stdafx.cpp │   │   ├── [ 270] stdafx.h │   │   ├── [ 314] targetver.h │   │   └── [1.3K] typed_buffer.h │   └── [4.0K] Exploit │   ├── [4.5K] Exploit.cpp │   ├── [1.2K] Exploit.filters │   ├── [1.1K] Exploit.sln │   ├── [5.0K] Exploit.vcxproj │   ├── [ 168] Exploit.vcxproj.user │   ├── [ 300] stdafx.cpp │   ├── [ 462] stdafx.h │   └── [ 314] targetver.h ├── [270K] ILEX-Exploit.ps1 └── [ 182] README.md 3 directories, 33 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.