目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2017-8759 PoC — Microsoft .NET Framework 安全漏洞

来源
关联漏洞
标题: Microsoft .NET Framework 安全漏洞 (CVE-2017-8759)
Description:Microsoft .NET Framework是美国微软(Microsoft)公司开发的一种全面且一致的编程模型,也是一个用于构建Windows、Windows Store、Windows Phone、Windows Server和Microsoft Azure的应用程序的开发平台。该平台包括C#和Visual Basic编程语言、公共语言运行库和广泛的类库。 Microsoft .NET Framework中存在远程代码执行漏洞。远程攻击者可借助恶意的文档或引用程序利用该漏洞执行代码。以下版本受到影响
Description
CVE-2017-8759 - A vulnerability in the SOAP WDSL parser.
介绍
CVE-2017-8759 Weaponisation PoC
===============================

This repository contains data that can be used to weaponise the CVE-2017-8759 vulnerability. 

For full information visit https://www.mdsec.co.uk/blog/ to find the post related to this vulnerability.

As always, my research is aimed to help the community become more aware of rising threats as well as the adversary simulation community to better simulate realistic threats against our client base in order to better educate and inform them. My research should not be used against a target without prior consent.

Video for weaponisation can be found at https://www.youtube.com/watch?v=hlkx5uYBT1Y

Credits
=======
Credits to myself, Vincent Yiu @vysecurity for the weaponisation in RTF form with no interaction required.
Credits to @voulnet for the exploit.txt.
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →