
누락된 KB를 열거하고 유용한 권한 상승 취약점에 대한 익스플로잇을 제안합니다
Watson은 누락된 KB를 열거하고 권한 상승 취약점에 대한 익스플로잇을 제안하도록 설계된 .NET 도구입니다.
C:\> Watson.exe
__ __ _
/ / /\ \ \__ _| |_ ___ ___ _ __
\ \/ \/ / _` | __/ __|/ _ \| '_ \
\ /\ / (_| | |_\__ \ (_) | | | |
\/ \/ \__,_|\__|___/\___/|_| |_|
v2.0
@_RastaMouse
[*] OS Build Number: 14393
[*] Enumerating installed KBs...
[!] CVE-2019-0836 : VULNERABLE
[>] https://exploit-db.com/exploits/46718
[>] https://decoder.cloud/2019/04/29/combinig-luafv-postluafvpostreadwrite-race-condition-pe-with-diaghub-collector-exploit-from-standard-user-to-system/
[!] CVE-2019-0841 : VULNERABLE
[>] https://github.com/rogue-kdc/CVE-2019-0841
[>] https://rastamouse.me/tags/cve-2019-0841/
[!] CVE-2019-1064 : VULNERABLE
[>] https://www.rythmstick.net/posts/cve-2019-1064/
[!] CVE-2019-1130 : VULNERABLE
[>] https://github.com/S3cur3Th1sSh1t/SharpByeBear
[!] CVE-2019-1253 : VULNERABLE
[>] https://github.com/padovah4ck/CVE-2019-1253
[!] CVE-2019-1315 : VULNERABLE
[>] https://offsec.almond.consulting/windows-error-reporting-arbitrary-file-move-eop.html
[*] Finished. Found 6 potential vulnerabilities.
패치 화요일 이후마다 Watson을 업데이트하려고 노력하지만, 잠재적인 오탐지의 경우 Windows 업데이트 카탈로그에서 최신 대체 정보를 확인하세요. 여전히 오류가 있다고 생각되면 Bug 레이블을 붙여 이슈를 등록하세요.
아직 포함되지 않은 특정 취약점을 Watson에서 보고 싶다면 Vulnerability Request 레이블을 붙여 이슈를 등록하고 CVE 번호를 포함하세요.
Watson에 포함된 취약점에 대한 좋은 익스플로잇을 알고 있다면 Exploit Suggestion 레이블을 붙여 이슈를 등록하고 익스플로잇의 URL을 제공하세요.