Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2021-42292 — Zeek 패키지로, 스프레드시트 다운로드의 네트워크 트래픽 분석을 통해 CVE-2021-42292 Microsoft Excel 로컬 권한 상승 익스플로잇을 탐지합니다. | Kitploit
도구/GitHubGitHub/corelight/cve-2021-42292
Vulnerability AnalysisExploitationNetwork SecurityThreat IntelligenceIntrusion DetectionIncident Response
GitHubcorelight/cve-2021-42292

CVE-2021-42292

Zeek 패키지로, 스프레드시트 다운로드의 네트워크 트래픽 분석을 통해 CVE-2021-42292 Microsoft Excel 로컬 권한 상승 익스플로잇을 탐지합니다.

저장소 보기
186124년 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

CVE-2021-42292

이 패키지는 CVE-2021-42292의 익스플로잇을 탐지합니다. 이 취약점은 Microsoft Excel의 로컬 권한 상승 취약점이며, notice.log에 알림을 생성합니다.

https://corelight.com/blog/detecting-cve-2021-42292

탐지 방법:

이 패키지는 트리거 역할을 하는 Excel 스프레드시트가 두 번째 스프레드시트를 다운로드할 때 취약점을 탐지합니다. 두 번째 스프레드시트는 상승된 권한으로 실행됩니다. 이 스크립트를 사용하여 Microsoft Excel이 Microsoft Excel 파일을 다운로드하는 것을 탐지할 수 있습니다. 모니터링 중인 일부 실시간 네트워크에서의 테스트 결과, 이 조합은 매우 드물었으며 현재까지 오탐(false positive)은 발견되지 않았습니다.

사용법:

$ zeek -Cr excelsploit_1.pcap packages

$ cat notice.log
#separator \x09
#set_separator  ,
#empty_field    (empty)
#unset_field    -
#path   notice
#open   2021-11-10-10-56-50
#fields ts      uid     id.orig_h       id.orig_p       id.resp_h       id.resp_p       fuid    file_mime_type  file_desc       proto   note    msg     sub     src     dst     p       n       peer_descr      actions email_dest      suppress_for    remote_location.country_code    remote_location.region  remote_location.city    remote_location.latitude        remote_location.longitude
#types  time    string  addr    port    addr    port    string  string  string  enum    enum    string  string  addr    addr    port    count   string  set[enum]       set[string]     interval        string  string  string  double  double
1636433584.277654       CeV1DA2EM1pRTfgWkc      127.0.0.1       51543   127.0.0.1       80      -       -       -       tcp     CVE_2021_42292::CVE_2021_42292  127.0.0.1 may be compromised by CVE-2021-42292, MS Office Excel download using Office from 127.0.0.1 detected. See sub field for additional triage information  host='127.0.0.1', method='HEAD', user_agent='Microsoft Office Excel 2014', CONTENT-TYPE='application/vnd.ms-excel', uri='/replica.xls'      127.0.0.1       127.0.0.1       80      -       -       Notice::ACTION_LOG      (empty) 3600.000000     -       -       -       -       -
1636433584.311236       CgKWSM1bhhl7K8B6n8      127.0.0.1       51545   127.0.0.1       80      -       -       -       tcp     CVE_2021_42292::CVE_2021_42292  127.0.0.1 may be compromised by CVE-2021-42292, MS Office Excel download using Office from 127.0.0.1 detected. See sub field for additional triage information  host='127.0.0.1', method='GET', user_agent='Mozilla/4.0 (compatible; ms-office; MSOffice 16)', CONTENT-TYPE='application/vnd.ms-excel', uri='/replica.xls'  127.0.0.1       127.0.0.1       80      -       -       Notice::ACTION_LOG      (empty) 3600.000000     -       -       -       -       -
#close  2021-11-10-10-56-50

Zeek 패키지의 탐지 방법론을 반영하는 Suricata 규칙도 제공됩니다.

링크:

  • 코드 요소 설명이 포함된 관련 블로그:
    • https://corelight.com/blog/detecting-cve-2021-42292
  • MIME 유형:
    • https://developer.mozilla.org/en-US/docs/Web/HTTP/Basics_of_HTTP/MIME_types/Common_types
  • Excel 사용자 에이전트:
    • https://developers.whatismybrowser.com/useragents/explore/software_name/excel/
도구 다운로드