Sploitus

Exploit for CVE-2017-0213 CVE-2017-0213 CVE-2017-8464 CVE-2018-0833 CVE-2018-8120

gitee ยท 2021-05-02

Exploit Code

MARKDOWN97 lines
## https://sploitus.com/exploit?id=67EAC56F-427E-5768-9279-DE409C7F6F05
# windows-kernel-exploits

### ็ฎ€ไป‹

windows-kernel-exploits

***

#### ๆผๆดžๅˆ—่กจ
##### #Security Bulletin   #KB     #Description    #Operating System ย 
- [MS17-017](./MS17-017) ใ€€[KB4013081]ใ€€ใ€€[GDI Palette Objects Local Privilege Escalation]ใ€€ใ€€(windows 7/8)
- [CVE-2017-8464](./CVE-2017-8464) ใ€€[LNK Remote Code Execution Vulnerability]ใ€€ใ€€(windows 10/8.1/7/2016/2010/2008)
- [CVE-2017-0213](./CVE-2017-0213) ใ€€[Windows COM Elevation of Privilege Vulnerability]ใ€€ใ€€(windows 10/8.1/7/2016/2010/2008)
- [CVE-2018-0833](./CVE-2018-0833)   [SMBv3 Null Pointer Dereference Denial of Service] ย  ย (Windows 8.1/Server 2012 R2)
- [CVE-2018-8120](./CVE-2018-8120)   [Win32k Elevation of Privilege Vulnerability]    (Windows 7 SP1/2008 SP2,2008 R2 SP1)
- [MS17-010](./MS17-010) ใ€€[KB4013389]ใ€€ใ€€[Windows Kernel Mode Drivers]ใ€€ใ€€(windows 7/2008/2003/XP)
- [MS16-135](./MS16-135) ใ€€[KB3199135]ใ€€ใ€€[Windows Kernel Mode Drivers]ใ€€ใ€€(2016)
- [MS16-111](./MS16-111) ใ€€[KB3186973]ใ€€ใ€€[kernel api]ใ€€ใ€€(Windows 10 10586 (32/64)/8.1)
- [MS16-098](./MS16-098) ใ€€[KB3178466]ใ€€ใ€€[Kernel Driver]ใ€€ใ€€(Win 8.1)
- [MS16-075](./MS16-075) ใ€€[KB3164038]ใ€€ใ€€[Hot Potato]ใ€€ใ€€(2003/2008/7/8/2012)
- [MS16-034](./MS16-034) ใ€€[KB3143145]ใ€€ใ€€[Kernel Driver]ใ€€ใ€€(2008/7/8/10/2012)
- [MS16-032](./MS16-032) ใ€€[KB3143141]ใ€€ใ€€[Secondary Logon Handle]ใ€€ใ€€(2008/7/8/10/2012)
- [MS16-016](./MS16-016) ใ€€[KB3136041]ใ€€ใ€€[WebDAV]ใ€€ใ€€(2008/Vista/7)
- [MS16-014](./MS16-014) ใ€€[K3134228]ใ€€ใ€€[remote code execution]ใ€€ใ€€(2008/Vista/7)
- [MS15-097](./MS15-097) ใ€€[KB3089656]ใ€€ใ€€[remote code execution]ใ€€ใ€€(win8.1/2012)
- [MS15-076](./MS15-076) ใ€€[KB3067505]ใ€€ใ€€[RPC]ใ€€ใ€€(2003/2008/7/8/2012)
- [MS15-077](./MS15-077) ใ€€[KB3077657]ใ€€ใ€€[ATM]ใ€€ใ€€(XP/Vista/Win7/Win8/2000/2003/2008/2012)
- [MS15-061](./MS15-061) ใ€€[KB3057839]ใ€€ใ€€[Kernel Driver]ใ€€ใ€€(2003/2008/7/8/2012)
- [MS15-051](./MS15-051) ใ€€[KB3057191]ใ€€ใ€€[Windows Kernel Mode Drivers]ใ€€ใ€€(2003/2008/7/8/2012)
- [MS15-015](./MS15-015) ใ€€[KB3031432]ใ€€ใ€€[Kernel Driver]ใ€€ใ€€(Win7/8/8.1/2012/RT/2012 R2/2008 R2)
- [MS15-010](./MS15-010) ใ€€[KB3036220]ใ€€ใ€€[Kernel Driver]ใ€€ใ€€(2003/2008/7/8)
- [MS15-001](./MS15-001) ใ€€[KB3023266]ใ€€ใ€€[Kernel Driver]ใ€€ใ€€(2008/2012/7/8)
- [MS14-070](./MS14-070) ใ€€[KB2989935]ใ€€ใ€€[Kernel Driver]ใ€€ใ€€(2003)
- [MS14-068](./MS14-068) ใ€€[KB3011780]ใ€€ใ€€[Domain Privilege Escalation]ใ€€ใ€€(2003/2008/2012/7/8)
- [MS14-058](./MS14-058) ใ€€[KB3000061]ใ€€ใ€€[Win32k.sys]ใ€€ใ€€(2003/2008/2012/7/8)
- [MS14-066](./MS14-066) ใ€€[KB2992611]ใ€€ใ€€[Windows Schannel Allowing remote code execution] (VistaSP2/7 SP1/8/Windows 8.1/2003 SP2/2008 SP2/2008 R2 SP1/2012/2012 R2/Windows RT/Windows RT 8.1)
- [MS14-040](./MS14-040) ใ€€[KB2975684]ใ€€ใ€€[AFD Driver]ใ€€ใ€€(2003/2008/2012/7/8)
- [MS14-002](./MS14-002) ใ€€[KB2914368]ใ€€ใ€€[NDProxy]ใ€€ใ€€(2003/XP)  
- [MS13-053](./MS13-053) ใ€€[KB2850851]ใ€€ใ€€[win32k.sys]ใ€€ใ€€(XP/Vista/2003/2008/win 7)  
- [MS13-046](./MS13-046) ใ€€[KB2840221]ใ€€ใ€€[dxgkrnl.sys]ใ€€ใ€€(Vista/2003/2008/2012/7)  
- [MS13-005](./MS13-005) ใ€€[KB2778930]ใ€€ใ€€[Kernel Mode Driver]ใ€€ใ€€(2003/2008/2012/win7/8)  
- [MS12-042](./MS12-042) ใ€€[KB2972621]ใ€€ใ€€[Service Bus]ใ€€ใ€€(2008/2012/win7)
- [MS12-020](./MS12-020) ใ€€[KB2671387]ใ€€ใ€€[RDP]ใ€€ใ€€(2003/2008/7/XP)
- [MS11-080](./MS11-080) ใ€€[KB2592799]ใ€€ใ€€[AFD.sys]ใ€€ใ€€(2003/XP)
- [MS11-062](./MS11-062) ใ€€[KB2566454]ใ€€ใ€€[NDISTAPI]ใ€€ใ€€(2003/XP)
- [MS11-046](./MS11-046) ใ€€[KB2503665]ใ€€ใ€€[AFD.sys]ใ€€ใ€€(2003/2008/7/XP)
- [MS11-011](./MS11-011) ใ€€[KB2393802]ใ€€ใ€€[kernel Driver]ใ€€ใ€€(2003/2008/7/XP/Vista)
- [MS10-092](./MS10-092) ใ€€[KB2305420]ใ€€ใ€€[Task Scheduler]ใ€€ใ€€(2008/7)  
- [MS10-065](./MS10-065) ใ€€[KB2267960]ใ€€ใ€€[FastCGI]ใ€€ใ€€(IIS 5.1, 6.0, 7.0, and 7.5)  
- [MS10-059](./MS10-059) ใ€€[KB982799]ใ€€ใ€€ [ACL-Churraskito]ใ€€ใ€€(2008/7/Vista)  
- [MS10-048](./MS10-048) ใ€€[KB2160329]ใ€€ใ€€[win32k.sys]ใ€€ใ€€(XP SP2 & SP3/2003 SP2/Vista SP1 & SP2/2008 Gold & SP2 & R2/Win7)  
- [MS10-015](./MS10-015) ใ€€[KB977165]ใ€€ใ€€ [KiTrap0D]ใ€€ใ€€(2003/2008/7/XP)  
- [MS10-012](./MS10-012) ใ€€[KB971468]ใ€€ใ€€[SMB Client Trans2 stack overflow]ใ€€ใ€€(Windows 7/2008R2)  
- [MS09-050](./MS09-050) ใ€€[KB975517]ใ€€ใ€€ [Remote Code Execution]ใ€€ใ€€(2008/Vista)  
- [MS09-020](./MS09-020) ใ€€[KB970483]ใ€€ใ€€ [IIS 6.0]ใ€€ใ€€(IIS 5.1 and 6.0)  
- [MS09-012](./MS09-012) ใ€€[KB959454]ใ€€ใ€€ [Chimichurri]ใ€€ใ€€(Vista/win7/2008/Vista)  
- [MS08-068](./MS08-068) ใ€€[KB957097]ใ€€ใ€€ [Remote Code Execution]ใ€€ใ€€(2000/XP)  
- [MS08-067](./MS08-067) ใ€€[KB958644]ใ€€ใ€€ [Remote Code Execution]ใ€€ใ€€(Windows 2000/XP/Server 2003/Vista/Server 2008)  
- [MS08-066](./MS08-066) ใ€€[KB956803]ใ€€ใ€€ [AFD.sys]ใ€€ใ€€(Windows 2000/XP/Server 2003)  
- [MS08-025](./MS08-025) ใ€€[KB941693]ใ€€ใ€€ [Win32.sys]ใ€€ใ€€(XP/2003/2008/Vista)  
- [MS06-040](./MS06-040) ใ€€[KB921883]ใ€€ใ€€ [Remote Code Execution]ใ€€ใ€€(2003/xp/2000)  
- [MS05-039](./MS05-039) ใ€€[KB899588]ใ€€ใ€€ [PnP Service]ใ€€ใ€€(Win 9X/ME/NT/2000/XP/2003)  
- [MS03-026](./MS03-026) ใ€€[KB823980]ใ€€ใ€€ [Buffer Overrun In RPC Interface]ใ€€ใ€€(/NT/2000/XP/2003)  

### ๅทฅๅ…ท
- [็ผบๅคฑ่กฅไธๆฃ€ๆต‹](./win-exp-suggester)ใ€€[@GDSSecurity](https://github.com/GDSSecurity/Windows-Exploit-Suggester)

### ้กน็›ฎ็ปดๆŠค

+ **ourren**(sina weibo @ourren) 
+ **hx**(sina weibo @hx)
+ **Bearcat**(github @Bearcat)

### ๅ…่ดฃ่ฏดๆ˜Ž

่ฏทๅ‹ฟ็”จไบŽ้žๆณ•็š„็”จ้€”๏ผŒๅฆๅˆ™้€ ๆˆ็š„ไธฅ้‡ๅŽๆžœไธŽๆœฌ้กน็›ฎๆ— ๅ…ณใ€‚

### ๅ‚่€ƒ้“พๆŽฅ

- [Windows Kernel Exploits](https://pentestlab.blog/2017/04/24/windows-kernel-exploits/)
- [Windows-Exploit-Suggester](https://github.com/GDSSecurity/Windows-Exploit-Suggester)  
- [WindowsExploits](https://github.com/abatchy17/WindowsExploits)
- [Privilege-Escalation](https://github.com/AusJock/Privilege-Escalation)  
- [Windows Privilege Escalation Fundamentals](http://fuzzysecurity.com/tutorials/16.html)  
- [brianwrf/WinSystemHelper](https://github.com/brianwrf/WinSystemHelper)  
- [Vulners](https://vulners.com/landing)  
- [Windows Exploits](https://github.com/WindowsExploits/Exploits)  

### ่ฝฌ่ฝฝ

่ฝฌ่ฝฝ่ฏทๆณจๆ˜Žๆฅ่‡ชhttps://github.com/SecWiki/windows-kernel-exploits

### ่กฅๅ……ๅฎŒๅ–„
ๆฌข่ฟŽๅคงๅฎถ่กฅๅ……ๅฎŒๅ–„ใ€€[git_man@outlook.com](git_man@outlook.com)

©SecWiki 2017