** 説明
- CVE-2021-31166 の POC: Windows HTTP プロトコルスタックのリモートコード実行脆弱性
- antx によって 2021-09-27 に作成されました。
** 詳細
- [[./trigger.gif][Poc-Gif]]
** CVE 重要度
- attackComplexity: LOW
- attackVector: NETWORK
- availabilityImpact: HIGH
- confidentialityImpact: HIGH
- integrityImpact: HIGH
- privilegesRequired: NONE
- scope: CHANGED
- userInteraction: NONE
- version: 3.1
- baseScore: 9.8
- baseSeverity: CRITICAL
** 影響を受けるシステム
- Windows Server, version 2004 (or 20H1) (Server Core installation),
- Windows 10 Version 2004 (or 20H1) for ARM64/x64/32-bit Systems,
- Windows Server, version 20H2 (Server Core Installation),
- Windows 10 Version 20H2 for ARM64/x64/32-bit Systems.
- Windows Remote Management (WinRM)
- Web Services on Devices (WSDAPI)
- KB4598481、KB5003173、KB5000736 の Windows システムパッチが未適用、またはシステム ISO が 2021-05 より前である場合。
** POC
- [[./CVE-2021-31166.py][Python-Poc]]
- [[./main.go][Golang-Poc]]
** 参照
- 参照ソース
- [[https://github.com/0vercl0k/CVE-2021-31166][0vercl0k/CVE-2021-31166]]
- 参照記事
- [[https://www.freebuf.com/vuls/281302.html][CVE-2021-31166 Windows HTTP プロトコルスタックリモートコード実行脆弱性の再現]]
- リスク情報
- [[https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-31166][HTTP プロトコルスタックのリモートコード実行脆弱性]]
- [[https://nvd.nist.gov/vuln/detail/CVE-2021-31166][NVD]]
- CVE
- [[https://github.com/CVEProject/cvelist/blob/master/2021/31xxx/CVE-2021-31166.json][CVE-2021-31166]]