目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2019-1069 PoC — Microsoft Windows Task Scheduler 后置链接漏洞

来源
关联漏洞
标题: Microsoft Windows Task Scheduler 后置链接漏洞 (CVE-2019-1069)
Description:Microsoft Windows和Microsoft Windows Server都是美国微软(Microsoft)公司的产品。Microsoft Windows是一套个人设备使用的操作系统。Microsoft Windows Server是一套服务器操作系统。Windows Task Scheduler是其中的一个用于配置和管理自动任务计划的应用程序。 Microsoft Windows Task Scheduler中存在后置链接漏洞。该漏洞源于网络系统或产品未正确过滤表示非预期资源的链接或者快捷方式
Description
Privesc through import of Sheduled tasks + Hardlinks - CVE-2019-1069
介绍
# SharpPolarBear

This is a weaponized version for one of the Exploits published by SandboxEscaper from here (https://github.com/SandboxEscaper/polarbearrepo). 

Most of the code comes from rasta-mouse CollectorService repository (https://github.com/rasta-mouse/CollectorService). I just changed the CVE-2019-0841-Code from the original SandboxEscaper C++ Code to C# and added some checks.

I have also added the required binaries (schtasks.exe, schedsvc.dll + an exported Windows XP Job File), which are unpacked during runtime and deleted afterwards. So you just need one binary here.

Windows Defender seams to have a heuristic detection for Applications creating a hardlink from C:\windows\system32\tasks to a file in C:\windows\system32\. So with Defender this executable is most likely blocked/detected.

You have to run the executable twice to get a system shell. 

## Legal disclaimer:
Usage of SharpPolarBear for attacking targets without prior mutual consent is illegal. It's the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program. Only use for educational / pentesting purposes.
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →