
Exploit para CVE-2021-1675 (PrintNightmare) que permite la elevación de privilegios a nivel de SYSTEM local y remoto en Windows a través del servicio Print Spooler. Incluye integración con el módulo Ladon.
http://k8gege.org/p/CVE-2021-1675.html
El 9 de junio, Microsoft publicó el parche de actualización de seguridad de junio, que corrigió 50 vulnerabilidades de seguridad, incluida una vulnerabilidad de escalada de privilegios en Windows Print Spooler, con el número de CVE: CVE-2021-1675. Un atacante remoto no autenticado podría explotar esta vulnerabilidad para ejecutar código arbitrario con privilegios de SYSTEM en el controlador de dominio, obteniendo así el control de todo el dominio. Se recomienda a los usuarios afectados que actualicen el parche de la vulnerabilidad a tiempo para protegerse, y que realicen una autocomprobación de activos y trabajos de prevención para evitar ataques de hackers.
Print Spooler es un servicio en los sistemas Windows utilizado para gestionar asuntos relacionados con la impresión.
Esta vulnerabilidad, bajo las condiciones adecuadas en un entorno de dominio, sin necesidad de interacción del usuario, permite a un atacante remoto no autenticado explotarla para ejecutar código arbitrario con privilegios de SYSTEM en el controlador de dominio, obteniendo así el control de todo el dominio.
Windows Server 2012 R2 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 (Server Core installation)
Windows Server 2012
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows RT 8.1
Windows 8.1 for x64-based systems
Windows 8.1 for 32-bit systems
Windows 7 for x64-based Systems Service Pack 1
Windows 7 for 32-bit Systems Service Pack 1
Windows Server 2016 (Server Core installation)
Windows Server 2016
Windows 10 Version 1607 for x64-based Systems
Windows 10 Version 1607 for 32-bit Systems
Windows 10 for x64-based Systems
Windows 10 for 32-bit Systems
Windows Server, version 20H2 (Server Core Installation)
Windows 10 Version 20H2 for ARM64-based Systems
Windows 10 Version 20H2 for 32-bit Systems
Windows 10 Version 20H2 for x64-based Systems
Windows Server, version 2004 (Server Core installation)
Windows 10 Version 2004 for x64-based Systems
Windows 10 Version 2004 for ARM64-based Systems
Windows 10 Version 2004 for 32-bit Systems
Windows 10 Version 21H1 for 32-bit Systems
Windows 10 Version 21H1 for ARM64-based Systems
Windows 10 Version 21H1 for x64-based Systems
Windows 10 Version 1909 for ARM64-based Systems
Windows 10 Version 1909 for x64-based Systems
Windows 10 Version 1909 for 32-bit Systems
Windows Server 2019 (Server Core installation)
Windows Server 2019
Windows 10 Version 1809 for ARM64-based Systems
Windows 10 Version 1809 for x64-based Systems
Windows 10 Version 1809 for 32-bit Systems
Ladon >= 8.6
Ladon CVE-2021-1675 DllPath
Ladon CVE-2021-1675 c:\evil.dll Ladon PrintNightmare c:\evil.dll
Win2019
Win2016
Win10
Win2016
C++、Python、C#、PowerShell https://github.com/afwu/PrintNightmare https://github.com/cube0x0/CVE-2021-1675 https://github.com/calebstewart/CVE-2021-1675
https://github.com/k8gege/LadonGo/releases
Versiones históricas: https://github.com/k8gege/Ladon/releases Versión 7.0: http://k8gege.org/Download Versión 8.6: K8小密圈