** Descrizione
- POC per CVE-2021-31166: Vulnerabilità di esecuzione remota di codice nello stack HTTP di Windows
- creato da antx il 2021-09-27.
** Dettaglio
- [[./trigger.gif][PoC-GIF]]
** Gravità CVE
- attackComplexity: LOW
- attackVector: NETWORK
- availabilityImpact: HIGH
- confidentialityImpact: HIGH
- integrityImpact: HIGH
- privilegesRequired: NONE
- scope: CHANGED
- userInteraction: NONE
- version: 3.1
- baseScore: 9.8
- baseSeverity: CRITICAL
** Sistemi interessati
- Windows Server, versione 2004 (o 20H1) (installazione Server Core),
- Windows 10 Versione 2004 (o 20H1) per sistemi ARM64/x64/32-bit,
- Windows Server, versione 20H2 (installazione Server Core),
- Windows 10 Versione 20H2 per sistemi ARM64/x64/32-bit.
- Windows Remote Management (WinRM)
- Web Services on Devices (WSDAPI)
- Mancanza delle patch KB4598481, KB5003173, KB5000736 di Windows o ISO di sistema precedente a 2021-05.
** POC
- [[./CVE-2021-31166.py][Python-PoC]]
- [[./main.go][Golang-PoC]]
** Riferimenti
- Ref-Source
- [[https://github.com/0vercl0k/CVE-2021-31166][0vercl0k/CVE-2021-31166]]
- Ref-Article
- [[https://www.freebuf.com/vuls/281302.html][CVE-2021-31166: Replica della vulnerabilità di esecuzione remota di codice nello stack HTTP di Windows]]
- Ref-Rischio
- [[https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-31166][Vulnerabilità di esecuzione remota di codice nello stack HTTP]]
- [[https://nvd.nist.gov/vuln/detail/CVE-2021-31166][NVD]]
- CVE
- [[https://github.com/CVEProject/cvelist/blob/master/2021/31xxx/CVE-2021-31166.json][CVE-2021-31166]]