Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-9332 PoC — FabulaTech USB for Remote Desktop 安全漏洞

Source
Associated Vulnerability
Title:FabulaTech USB for Remote Desktop 安全漏洞 (CVE-2020-9332)
Description:FabulaTech USB for Remote Desktop是英国FabulaTech公司的一款USB设备远程连接应用程序,它支持将插入本地计算机的USB设备重定向到远程计算机。 FabulaTech USB for Remote Desktop 2020-02-19及之前版本中的ftusbbus2.sys文件存在安全漏洞。攻击者可借助与USB HID设备相关的特制IoCtl代码利用该漏洞提升权限。
Readme
# CVE-2020-9332
## Description
A vulnerable bus driver in FabulaTech “USB for Remote Desktop” and “USB over Network” allows low privileged users to add a fully controlled software USB device, which could be used by an attacker to elevate privileges under certain common circumstances

------------------------------------------
## [Vulnerability Type]
Incorrect Access Control

------------------------------------------
## [Vendor of Product]
FabulaTech

------------------------------------------
## [Affected Product Code Base]
USB for Remote Desktop

USB over Network

------------------------------------------
## [Attack Type]
Local

------------------------------------------
## [Impact Escalation of Privileges]
true

------------------------------------------
## [CVE Impact Other]
Adding trusted software USB HID device fully controlled by non-privileged users

------------------------------------------
## [Discoverer]
Michael Myngerbayev of SentinelOne

------------------------------------------
## [Reference]
https://www.fabulatech.com

https://labs.sentinelone.com/click-from-the-backyard-cve-2020-9332/
File Snapshot

[4.0K] /data/pocs/535ec4ebb82a0d44b93fa2b8a6f8d580eea425d0 └── [1.1K] README.md 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.