
CVE-2019-1388 UAC-Windows-Zertifikatsdialog ausnutzen
Beschreibung:
Dieser CVE-Exploit missbraucht den UAC-Windows-Zertifikatdialog, um den Zertifikataussteller-Link als NT-Authority-Benutzer auszuführen und einen Browser zu öffnen, der unter NT-Authority-Benutzer läuft. Dann können wir das nutzen, um eine Shell als NT-Authority-Benutzer zu starten.
Schritte:
1) find a program that can trigger the UAC prompt screen
2) select "Show more details"
3) select "Show information about the publisher's certificate"
4) click on the "Issued by" URL link it will prompt a browser interface.
5) wait for the site to be fully loaded & select "save as" to prompt a explorer window for "save as".
6) on the explorer window address path, enter the cmd.exe full path:
C:\WINDOWS\system32\cmd.exe
7) now you'll have an escalated privileges command prompt.
Video PoC: https://www.youtube.com/watch?v=RW5l6dQ8H-8