目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2020-10551 PoC — Tencent QQBrowser 安全漏洞

来源
关联漏洞
标题: Tencent QQBrowser 安全漏洞 (CVE-2020-10551)
Description:Tencent QQBrowser是中国腾讯(Tencent)公司的一款Web浏览器。 Tencent QQBrowser 10.5.3870.400之前版本中存在安全漏洞,该漏洞源于NT AUTHORITYAuthenticated Users组群中的人员可以编写TsService.exe文件。本地攻击者可通过向TsService所在位置写入恶意的可执行文件利用该漏洞将权限提升至NT AUTHORITYSYSTEM。
Description
Privilege escalation in QQBrowser
介绍
**CVEID**: CVE-2020-10551

**Name of the affected product(s) and version(s)**: QQBrowser (all versions prior to 10.5.3870.400)

**Problem type**: CWE-284: Improper Access Control

---

**Summary**

QQBrowser is a web browser developed by Tencent. It is one of the most popular web browsers used in China.
During our tests, we have found a vulnerability which allows an unprivileged local attacker to gain code
execution as NT AUTHORITY\SYSTEM.
     
All version of QQBrowser prior to 10.5.3870.400 do not correctly set up ACLs for a TsService.exe file.
A malicious local attacker could overwrite the file to gain access to NT AUTHORITY\SYSTEM account, which
is the highest privileged account on a Windows system.
 
**Description**
 
QQBrowser creates a Windows service with ImagePath pointing to a TsService.exe file in its installation directory
(default: C:\Program Files (x86)\Tencent\QQBrowser\TsService.exe). This file’s permissions allow for writing by members
of NT AUTHORITY\Authenticated Users group which by default includes all users. An attacker could exploit the vulnerability
by replacing TsService.exe with his own executable, which would then be invoked with NT AUTHORITY\SYSTEM privileges.
 
**Reproduction**
 
Delete TsService.exe and replace it with a different program. Reboot the system.

**Remedy**

Install a newer version of QQBrowser.
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →