
CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit
Malicious docx generator to exploit CVE-2021-40444 (Microsoft Office Word Remote Code Execution), works with arbitrary DLL files.
Now the generator is able to generate the document required to exploit also the "Follina" attack (leveraging ms-msdt).
Although many PoC are already around the internet, I guessed to give myself a run to weaponizing this vulnerability, as what I found available lacked valuable information that it's worth sharing, also considering Microsoft already released a patch for this vulnerability.
So far, the only valuable resources I've seen to create a fully working generator are:
The above resources outline a lot of the requirements needed to create a full chain. To avoid repeating too much unnecessary information, I'll just summarize the relevant details.
There are quite a bit of overlooked requirements for this exploit to work, which caused even good PoCs, like the one by lockedbyte, to fail working properly.
Maybe nobody explicitly "released" them to avoid the vulnerability to be exploited more. But now it's patched, so it should not cause a lot of troubles to release the details.
As for this tweet by Will Dormann, the HTML should be at least 4096 bytes in size in order to trigger the "Preview" within MS Word.
The CAB file needs to be byte-patched to avoid extraction errors and to achieve the ZipSlip:
filename.inf should become ../filename.inffilename.inf coffCabStartCFFOLDER.typeCompress CFFOLDER.coffCabStart should be increased by 3 (due to the added '../'')CFFOLDER.cCfData CFFILE.cbFile should be greater than the whole CFHEADER.cbCabinetCFDATA.csum The reason for these constraints are many, and I didn't spend enough time to deeply understand all of them, but let's see the most important:
NOTE1: Defender now detects if the CAB file contains a PE by using the _IMAGE_DOS_HEADER.e_magic value as a
signature, potentially avoiding PE files to be embedded in the CAB. Can this signature be bypassed?
I'm not sure but, as observed before, this is a patched vulnerability, so I'm not planning to invest much more time
on this. Up to the curious reader to develop this further.
NOTE2: Microsoft Patch blocks arbitrary URI schemes, apparently using a blacklist approach (this is just a supposition)
The main attack chain associated with CVE-2021-40444 is the DLL attack loaded via the .cpl URI scheme. In order to
exploit that, an attacker needs to generate a specially crafted DLL. If you want to test it out, try my evildll-gen
script.
As noted by Max Maluin, it is possible to interact with several filetypes abusing IE and the associated file extension based URI. While this is might be a good way to exploit IE, it has limitations.
Indeed, it should be noted that the method used in the exploit to download files is based on ActiveX control updates,
and cannot be used to download arbitrary files.
As per Microsoft documentation, the codebase tag
can point just to a few filetypes: OCX, INF and CAB.
Even if we can directly download an OCX or INF file, we still can't be sure to download the file in the right location
within the system. With the cab exploit, it is possible to move the .inf file in a well-known path using the path traversal,
but in any other case the file will be stored in a random directory, making it virtually impossible to reference it.
As of today, I didn't find a way to chain download and execution WITHOUT a CAB file.
Note: Talking about IE alone, HTML smuggling could be a possible scenario to exploit the vulnerability.
This technique was firstly disclosed by Eduardo Braun on Twitter and further explained in this paper.
Please note that using this technique, the attack chain is a bit different. This attack requires the user to download a specially crafted RAR file, obtained by chaining a valid WSF script and a valid RAR file. Once opened, the RAR will contain a DOCX with a reference to an HTML, which in turn will try to load the RAR file as a WSF script.
To summarise:
The generator utility can currently reproduce the following attacks: