Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2016-0034 PoC — Microsoft Silverlight运行时远程执行代码漏洞

Source
Associated Vulnerability
Title:Microsoft Silverlight运行时远程执行代码漏洞 (CVE-2016-0034)
Description:Microsoft Silverlight是美国微软(Microsoft)公司的一套开发平台。该平台可构建适用于Web、桌面和移动设备的交互式应用程序。 Microsoft Silverlight 5.1.41212.0之前5版本中存在远程执行代码漏洞,该漏洞源于程序使用恶意解码器(可返回负偏移量从而导致Silverlight将不安全的对象标题替换为攻击者提供的内容)解码字符串。远程攻击者可利用该漏洞获得与当前登录用户相同的权限。
Description
CVE-2016-0034 Decompile
Readme
# CVE-2016-0034-Decompile


CVE-2016-0034  is a bug that affects Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code Execution Vulnerability." 


CVE-2016-0034 Decompile Source that was used by Rig Exploit Kit in the wild.
File Snapshot

[4.0K] /data/pocs/674b9dbbc5d6325ef3a7e153b21b461d06b9335c ├── [ 276] App.xaml ├── [2.3K] App.xaml.cs ├── [ 803] eilquO2RA2sF4k0Luh.cs ├── [ 33K] exploit.cs ├── [ 452] MainPage.xaml ├── [ 454] MainPage.xaml.cs └── [ 432] README.md 0 directories, 7 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.