
CVE-2019-1388 Abus de la boîte de dialogue de certificat Windows UAC
Description :
Cet exploit CVE tend à abuser de la boîte de dialogue de certificat UAC Windows pour exécuter le lien de l'émetteur du certificat en tant qu'utilisateur NT Authority et ouvrir un navigateur qui est sous l'utilisateur NT Authority. Ensuite, nous pouvons l'utiliser pour lancer un shell en tant qu'utilisateur NT Authority.
Étapes :
1) find a program that can trigger the UAC prompt screen
2) select "Show more details"
3) select "Show information about the publisher's certificate"
4) click on the "Issued by" URL link it will prompt a browser interface.
5) wait for the site to be fully loaded & select "save as" to prompt a explorer window for "save as".
6) on the explorer window address path, enter the cmd.exe full path:
C:\WINDOWS\system32\cmd.exe
7) now you'll have an escalated privileges command prompt.
Vidéo PoC : https://www.youtube.com/watch?v=RW5l6dQ8H-8