目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2021-21551 PoC — Dell dbutil Driver 安全漏洞

来源
关联漏洞
标题: Dell dbutil Driver 安全漏洞 (CVE-2021-21551)
Description:Dell dbutil Driver是美国戴尔(Dell)公司的一个应用软件。提供了戴尔公司设备的一个驱动程序。 Dell dbutil Driver 存在安全漏洞,该漏洞源于戴尔dbutil驱动程序dbutil 2 .sys中不正确的访问限制。以下产品及版本受到影响:DBUtil: 2.3 。
Description
Script to patch your domain computers about the CVE-2021-21551. Privesc on machines that have the driver dbutil_2_3.sys, installed by some DELL tools (BIOS updater, SupportAssist...)
介绍
# Description
Script to patch your domain computers about the CVE-2021-21551. Privesc on machines that have the driver dbutil_2_3.sys, installed by some DELL tools (BIOS updater, SupportAssist...). It uses WinRM to invoke the checks on every domain-member computers. Tries to clean the vulnerable drivers & fullfill a .txt list with status.

# Usage - Remote version
1. Just launch the script, it does the job :)  
`PS> ./CVE-2021-21551-remotefix.ps1`

// Make sure that your clients are accessible with WinRM (PSRemoting). //  
// Else not, you can modify the script to run locally by a scheduled task, pushed by GPO. //

# Usage - Local version
`PS> ./CVE-2021-21551-localfix.ps1`  
In case that you can't access to your domain computers with WinRM, you can push that script with a GPO scheduled task.  
It will execute the script locally, clean the driver(s) and notify results by e-mail.  

1. Update these these 3 args :  
![image](https://user-images.githubusercontent.com/41639163/122671545-7fef0500-d1c7-11eb-9824-5da55c78ef09.png)  

2. Create a GPO targeted to your computers to run the script
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →