
Proof-of-concept exploit for CVE-2024-57394: low-privilege file restoration to System32 enabling DLL hijacking and local privilege escalation to SYSTEM via StorSvc.
A vulnerability was identified in the Qi-ANXIN Tianqing Endpoint Security Management System (tested on version 10.0). This vulnerability allows low-privilege users to restore a quarantined file to an arbitrary location, such as C:\Windows\System32.
An attacker can craft a malicious DLL file, restore it to C:\Windows\System32, and exploit known DLL hijacking vulnerabilities (e.g., LPE via StorSvc) to escalate privileges to SYSTEM.
Craft a malicious DLL named sprintcsp.dll that executes malicious commands.

Land the DLL on the target machine, the file gets quarantined.

Restore and trust the file in the EDR client.

File is successfully written to C:\Windows\System32.

Create RpcClient.exe, which leverage a DLL hijacking vulnerability in the StorSvc service to execute the malicious DLL sprintcsp.dll.
As a proof of concept, the DLL will create a service named abc and execute the binary at C:\Users\Public\test.exe as SYSTEM.
Reference: https://github.com/blackarrowsec/redteam-research/tree/master/LPE%20via%20StorSvc