
CVE-2019-1388 UAC विंडोज सर्टिफिकेट डायलॉग का दुरुपयोग करें
विवरण:
यह CVE एक्सप्लॉइट UAC विंडोज प्रमाणपत्र डायलॉग का दुरुपयोग करता है ताकि प्रमाणपत्र जारीकर्ता लिंक को NT Authority User के रूप में निष्पादित किया जा सके और NT Authority User के अंतर्गत एक ब्राउज़र खोला जा सके। फिर हम उसका उपयोग NT Authority User के रूप में शेल प्राप्त करने के लिए कर सकते हैं।
चरण:
1) find a program that can trigger the UAC prompt screen
2) select "Show more details"
3) select "Show information about the publisher's certificate"
4) click on the "Issued by" URL link it will prompt a browser interface.
5) wait for the site to be fully loaded & select "save as" to prompt a explorer window for "save as".
6) on the explorer window address path, enter the cmd.exe full path:
C:\WINDOWS\system32\cmd.exe
7) now you'll have an escalated privileges command prompt.
वीडियो PoC: https://www.youtube.com/watch?v=RW5l6dQ8H-8