Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-4331 PoC — 多款Apple产品 Heimdal 缓冲区错误漏洞

Source
Associated Vulnerability
Title:多款Apple产品 Heimdal 缓冲区错误漏洞 (CVE-2018-4331)
Description:Apple iOS等都是美国苹果(Apple)公司的产品。Apple iOS是一套为移动设备所开发的操作系统。Apple tvOS是一套智能电视操作系统。Apple macOS Mojave是一套专为Mac计算机所开发的专用操作系统。Heimdal是其中的一个反恶意软件组件。 多款Apple产品中的Heimdal组件存在缓冲区错误漏洞。攻击者可利用该漏洞以系统权限执行任意代码(内存损坏)。以下产品和版本受到影响:Apple iOS 12之前版本;macOS Mojave 10.14之前版本;tvOS 12
Description
CVE-2018-4331: Exploit for a race condition in the GSSCred system service on iOS 11.2.
File Snapshot

[4.0K] /data/pocs/3d0961ead137d87d217133bc7dfb4f5183b59c8f ├── [4.0K] gsscred_race │   ├── [8.0K] apple_private.h │   ├── [4.0K] arm64 │   │   ├── [4.2K] arm64_payload.c │   │   ├── [1.1K] arm64_payload.h │   │   ├── [2.2K] gadgets.c │   │   ├── [1.1K] gadgets.h │   │   └── [ 22K] payload_strategy_1.c │   ├── [ 49K] gsscred_race.c │   ├── [2.7K] gsscred_race.h │   ├── [ 922] log.c │   ├── [ 751] log.h │   ├── [ 382] main.c │   ├── [6.9K] payload.c │   └── [2.2K] payload.h ├── [4.0K] gsscred_race_ios │   ├── [4.0K] gsscred_race_ios │   │   ├── [ 290] AppDelegate.h │   │   ├── [2.2K] AppDelegate.m │   │   ├── [4.0K] Assets.xcassets │   │   │   └── [4.0K] AppIcon.appiconset │   │   │   └── [1.6K] Contents.json │   │   ├── [4.0K] Base.lproj │   │   │   ├── [1.6K] LaunchScreen.storyboard │   │   │   └── [1.6K] Main.storyboard │   │   ├── [1.4K] Info.plist │   │   ├── [ 338] main.m │   │   ├── [ 228] ViewController.h │   │   └── [ 497] ViewController.m │   └── [4.0K] gsscred_race_ios.xcodeproj │   ├── [ 17K] project.pbxproj │   └── [4.0K] project.xcworkspace │   └── [ 161] contents.xcworkspacedata └── [1.2K] Makefile 9 directories, 25 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.