173

GitHub - rxwx/CVE-2018-0802: PoC Exploit for CVE-2018-0802 (and optionally CVE-2...

 6 years ago
source link: https://github.com/rxwx/CVE-2018-0802
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

CVE-2018-0802

packager_exec CVE-2018-0802

This repo contains a Proof of Concept exploit for CVE-2018-0802. To get round the limited command length allowed, the exploit uses the Packager OLE object to drop an embedded payload into the %TMP% directory, and then executes the file using a short command via a WinExec call, such as: cmd.exe /c%TMP%\file.exe.

Usage

packager_exec_CVE-2018-0802.py -e executable_path -o output_file_name

Add the -d option to exploit both CVE-2017-11882 and CVE-2018-0802 in the same document.

Detection

I've added a Yara rule to detect this specific variant of the exploit as used itw. Please note that this can be easily bypassed and may need tweaking. Happy to take PR's for better ones ;)

Greetz

This exploit is based heavily on the prior work already done by Embedi on CVE-2017-11882. I take no credit for the great work already achieved by those mentioned here.

Kudos also goes out to the many discoverers:

  • bee13oy of Qihoo 360 Vulcan Team
  • zhouat of Qihoo 360 Vulcan Team
  • Liang Yin of Tencent PC Manager
  • Luka Treiber of 0patch Team - ACROS Security
  • Netanel Ben Simon and Omer Gull of Check Point Software Technologies
  • Yang Kang, Ding Maoyin and Song Shenlei of Qihoo 360 Core Security (@360CoreSec)
  • Yuki Chen of Qihoo 360 Vulcan Team
  • Zhiyuan Zheng

Sample exploit for CVE-2018-0802 (starting calc.exe as payload)

example folder holds an .rtf file which exploits CVE-2018-0802 vulnerability and runs calculator in the system.


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK