POC详情: b6c768a6ef4ea6572be726b34ee707a2ce59a5d6

来源
关联漏洞
标题: Android 资源管理错误漏洞 (CVE-2019-2215)
描述:Android是美国谷歌(Google)和开放手持设备联盟(简称OHA)的一套以Linux为基础的开源操作系统。 Android中的binder.c文件存在资源管理错误漏洞。攻击者可利用该漏洞提升权限。
描述
This is a bad-binder exploit affecting the android binder IPC system that was used in the wild discovered by P0
介绍
### Bad-Binder (CVE-2019-2215)
The following is the exploit for the **bad binder** *(CVE-2019-2215)* vulnz that was tested on an x86 Emulator. The aim was to abuse the UAF vulnerability to trigger an AAR primitive to leak kernel addresses and use an AAW primitive to overwrite `addr_limit` leading to a Kernel Read and Write primitive allowing us to modify the `cred_struct` for Local-Priviledge-Escalation `(LPE)`.

### Credits
- https://googleprojectzero.blogspot.com/2019/11/bad-binder-android-in-wild-exploit.html
- https://cloudfuzz.github.io/android-kernel-exploitation/chapters/exploitation.html#exploit-in-action
文件快照

[4.0K] /data/pocs/b6c768a6ef4ea6572be726b34ee707a2ce59a5d6 ├── [9.9K] exploit.c └── [ 621] README.md 0 directories, 2 files
神龙机器人已为您缓存
备注
    1. 建议优先通过来源进行访问。
    2. 如果因为来源失效或无法访问,请发送邮箱到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
    3. 神龙已为您对POC代码进行快照,为了长期维护,请考虑为本地POC付费,感谢您的支持。