Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
DetectPacket-CVE-2017-8464 — Exploit vulnerabilities and vulnerability prevention implementation | Kitploit
Tools/GitHubGitHub/trg-1999/detectpacket-cve-2017-8464
Packet Sniffing & AnalysisStatic AnalysisVulnerability AnalysisExploitationForensicsNetwork SecurityMalware AnalysisIntrusion DetectionLearning & Education
GitHubtrg-1999/detectpacket-cve-2017-8464

DetectPacket-CVE-2017-8464

Exploit vulnerabilities and vulnerability prevention implementation

View Repository
21544 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Building a Vulnerability Detection Application for CVE-2017-8464

Source (click here)

CONTENTS:

PART 1: OVERVIEW OF CVE-2017-8464

  1. CONCEPT OF LNK FILE
  2. CREATING A SYSTEM VULNERABLE TO CVE-2017-8464
  3. TOOLS FOR EXPLOITING CVE-2017-8464

PART 2: USING METASPLOIT TO EXPLOIT CVE-2017-8464

2.1. EXPLOITATION MODEL FOR CVE-2017-8464

2.2. EXECUTING THE EXPLOIT FOR CVE-2017-8464

PART 3: BUILDING A CVE-2017-8464 DETECTION TOOL USING PYTHON

3.1. ANALYZING THE SIGNATURE OF CVE-2017-8464 BASED ON CAPTURED NETWORK PACKETS

3.2. FUNCTION TO DETECT CVE-2017-8464 EXPLOITS BASED ON PACKET SIGNATURE ANALYSIS

CONCLUSION

**

PART 1: OVERVIEW OF CVE-2017-8464

  1. CONCEPT OF LNK FILE

LNK is a System File - Windows Shortcut, in Binary format developed by Microsoft.

Figure 1: Shortcut icon on Windows

An LNK file is a shortcut or "link" used by Windows as a reference to an original file, folder, or application, similar to an alias on the Macintosh platform. It contains the shortcut's target type, location, and filename, as well as the programs that open the target files and an optional shortcut key. These files can be created in Windows by right-clicking a file, folder, or executable and then selecting Create shortcut.

This vulnerability exists in Microsoft Windows and allows an attacker to execute remote code if the icon of a specially crafted shortcut is processed.

Figure 2: Manually creating a shortcut that executes, loads, and runs attack code via .LNK file

The vulnerable component is linked to the network stack. Such a vulnerability is often called “remotely exploitable” and can be considered an attack that can be exploited at the protocol level or across multiple network hops (e.g., through one or more routers).

  1. CREATING A SYSTEM VULNERABLE TO CVE-2017-8464

Systems affected by CVE-2017-8464 are the Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016, which allow local users or remote attackers to execute arbitrary code via a specially crafted .LNK file that is not properly handled when displaying icons in Windows Explorer or any other application that parses shortcut icons. Also known as the "LNK Remote Code Execution Vulnerability."

The security update fixes the vulnerability by correcting the validation of shortcut icon references. Microsoft Windows released an update for this vulnerability in June 2017. This vulnerability does not affect Windows XP and older Windows versions.

  1. TOOLS FOR EXPLOITING CVE-2017-8464

Metasploit

Metasploit Framework is an environment for testing, attacking, and exploiting services using the command line interface. This tool is available on Kali Linux VMware version.

Figure 3: Metasploit Tool

Armitage

A graphical interface tool based on the Metasploit project.

Figure 4: Armitage Tool.

PART 2: USING METASPLOIT TO EXPLOIT CVE-2017-8464

2.1. EXPLOITATION MODEL FOR CVE-2017-8464

Victim machine – Windows 7 Pro

Figure 5: Victim's operating system version

Figure 6: Victim machine IP address

Attacker machine – Kali Linux – Using Metasploit.

Figure 7: Attacker machine IP address

The active network is VMnet8 Subnet 192.168.169.0

2.2. EXECUTING THE EXPLOIT FOR CVE-2017-8464

  • Create reverse_tcp payloads and listen for TCP connections to the Kali machine.
  • With LHOST being the listening address from the attacker machine.

Figure 8: Creating payloads and listening for TCP connections to the attacker machine

  • Create a shortcut file containing the CVE-2017-8464 vulnerability to automatically run the embedded reverse_tcp payload.

Figure 9: Creating a .lnk file that automatically runs malicious code

Figure 10: Payload setup information

  • Run the exploit command to initialize the vulnerable shortcuts pointing to the payload file.
  • Specifically, as described above, there will be a payload file named FlashPlayerCPApp.cpl and a shortcut file containing the vulnerability that automatically runs the payload file.
  • After creating all these necessary files, it will save them to the /root/.msf4/local/ folder on the attacker's machine. Then the attacker will copy all files in that folder to any USB drive.

Figure 11: Creating the .lnk file along with malicious code

Figure 12: Copying all malicious code to USB

  • After tricking the victim into plugging the USB into their computer, the victim does not need to click any application on the USB, but the vulnerability in the .lnk file (shortcut file) automatically triggers the malicious payload to execute the remote code execution exploit.

Figure 13: Victim plugs in USB containing malicious .lnk file

  • Observing the attacker machine, we see that the victim machine has connected to the attacker machine. At this point, the attacker has successfully exploited CVE-2017-8464 and executed malicious code remotely on the victim machine.

Figure 14: Attacker successfully exploited and gained access to the victim machine

**

PART 3: BUILDING A CVE-2017-8464 DETECTION TOOL USING PYTHON

3.1. ANALYZING THE SIGNATURE OF CVE-2017-8464 BASED ON CAPTURED NETWORK PACKETS

  • When capturing packets during the attack, we see that when the .lnk file automatically runs, the victim machine initiates a TCP connection to the attacker machine's address as set in the payload.

Figure 15: Attack packet on CVE-2017-8464 captured

  • A packet with the PSH flag allows direct sending to the victim machine instead of buffering.

Figure 16: Packet with PSH flag after successful TCP connection to attacker

Download Tool