
windows-kernel-exploits Windows 플랫폼 권한 상승 취약점 모음
# windows-kernel-exploits ### 개요 windows-kernel-exploits *** #### 취약점 목록 ##### #보안 공지 #KB #설명 #운영체제 - [CVE-2021-33739](https://github.com/mavillon1/CVE-2021-33739-POC) [Microsoft DWM Core Library 권한 상승 취약점] (Windows 10, 20) - [CVE-2021-1732](https://github.com/KaLendsi/CVE-2021-1732-Exploit) [Windows Win32k 권한 상승 취약점] (Windows 10, 2019/20H2) - [CVE-2020-0787](https://github.com/cbwang505/CVE-2020-0787-EXP-ALL-WINDOWS-VERSION) [Windows Background Intelligent Transfer Service 권한 상승 취약점] (Windows 7/8/10, 2008/2012/2016/2019) - [CVE-2020-0796](https://github.com/danigargu/CVE-2020-0796) [Microsoft Server Message Block 3.1.1(SMBv3) 프로토콜이 특정 요청을 처리하는 방식에 원격 코드 실행 취약점이 존재함, 일명 'Windows SMBv3 클라이언트/서버 원격 코드 실행 취약점'] (Windows 1903/1909) - [CVE-2019-1458](https://github.com/unamer/CVE-2019-1458) [Windows Win32k 구성 요소가 메모리 개체를 제대로 처리하지 못할 때 발생하는 권한 상승 취약점] (Windows 7/8/10/2008/2012/2016) - [CVE-2019-0803](https://github.com/ExpLife0011/CVE-2019-0803) [Windows Win32k 구성 요소가 메모리 개체를 제대로 처리하지 못할 때 발생하는 권한 상승 취약점] (Windows 7/8/10/2008/2012/2016/2019) - [CVE-2018-8639](https://github.com/ze0r/CVE-2018-8639-exp) [Windows Win32k 구성 요소가 메모리 개체를 제대로 처리하지 못할 때 발생하는 권한 상승 취약점] (Windows 7/8/10/2008/2012/2016) - [CVE-2018-1038](https://gist.github.com/xpn/3792ec34d712425a5c47caf5677de5fe) [Windows 커널 권한 상승 취약점] (Windows 7 SP1/Windows Server 2008 R2 SP1) - [CVE-2018-0743](https://github.com/saaramar/execve_exploit) [Linux용 Windows 하위 시스템 권한 상승 취약점] (Windows 10 버전 1703/Windows 10 버전 1709/Windows Server 버전 1709) - [CVE-2018-8453](https://github.com/ze0r/cve-2018-8453-exp) [Windows Win32k 구성 요소의 권한 상승 취약점] (>= Windows 8.1) - [CVE-2018-8440](https://github.com/sourceincite/CVE-2018-8440) [Windows ALPC 권한 상승 취약점] (Windows 7/8.1/10/2008/2012/2016) - [MS17-017](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS17-017) [KB4013081] [GDI 팔레트 개체 로컬 권한 상승] (Windows 7/8) - [CVE-2017-8464](https://github.com/secwiki/windows-kernel-exploits/blob/master/CVE-2017-8464) [LNK 원격 코드 실행 취약점] (Windows 10/8.1/7/2016/2010/2008) - [CVE-2017-0213](https://github.com/secwiki/windows-kernel-exploits/blob/master/CVE-2017-0213) [Windows COM 권한 상승 취약점] (Windows 10/8.1/7/2016/2010/2008) - [CVE-2018-0833](https://github.com/secwiki/windows-kernel-exploits/blob/master/CVE-2018-0833) [SMBv3 널 포인터 역참조 서비스 거부] (Windows 8.1/Server 2012 R2) - [CVE-2018-8120](https://github.com/secwiki/windows-kernel-exploits/blob/master/CVE-2018-8120) [Win32k 권한 상승 취약점] (Windows 7 SP1/2008 SP2,2008 R2 SP1) - [MS17-010](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS17-010) [KB4013389] [Windows 커널 모드 드라이버] (Windows 7/2008/2003/XP) - [MS16-135](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS16-135) [KB3199135] [Windows 커널 모드 드라이버] (2016) - [MS16-111](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS16-111) [KB3186973] [커널 API] (Windows 10 10586 (32/64)/8.1) - [MS16-098](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS16-098) [KB3178466] [커널 드라이버] (Win 8.1) - [MS16-075](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS16-075) [KB3164038] [Hot Potato] (2003/2008/7/8/2012) - [MS16-034](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS16-034) [KB3143145] [커널 드라이버] (2008/7/8/10/2012) - [MS16-032](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS16-032) [KB3143141] [보조 로그온 핸들] (2008/7/8/10/2012) - [MS16-016](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS16-016) [KB3136041] [WebDAV] (2008/Vista/7) - [MS16-014](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS16-014) [K3134228] [원격 코드 실행] (2008/Vista/7) - [MS15-097](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS15-097) [KB3089656] [원격 코드 실행] (Win8.1/2012) - [MS15-076](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS15-076) [KB3067505] [RPC] (2003/2008/7/8/2012) - [MS15-077](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS15-077) [KB3077657] [ATM] (XP/Vista/Win7/Win8/2000/2003/2008/2012) - [MS15-061](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS15-061) [KB3057839] [커널 드라이버] (2003/2008/7/8/2012) - [MS15-051](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS15-051) [KB3057191] [Windows 커널 모드 드라이버] (2003/2008/7/8/2012) - [MS15-015](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS15-015) [KB3031432] [커널 드라이버] (Win7/8/8.1/2012/RT/2012 R2/2008 R2) - [MS15-010](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS15-010) [KB3036220] [커널 드라이버] (2003/2008/7/8) - [MS15-001](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS15-001) [KB3023266] [커널 드라이버] (2008/2012/7/8) - [MS14-070](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS14-070) [KB2989935] [커널 드라이버] (2003) - [MS14-068](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS14-068) [KB3011780] [도메인 권한 상승] (2003/2008/2012/7/8) - [MS14-058](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS14-058) [KB3000061] [Win32k.sys] (2003/2008/2012/7/8) - [MS14-066](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS14-066) [KB2992611] [Windows Schannel 원격 코드 실행 허용] (Vista SP2/7 SP1/8/Windows 8.1/2003 SP2/2008 SP2/2008 R2 SP1/2012/2012 R2/Windows RT/Windows RT 8.1) - [MS14-040](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS14-040) [KB2975684] [AFD 드라이버] (2003/2008/2012/7/8) - [MS14-002](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS14-002) [KB2914368] [NDProxy] (2003/XP) - [MS13-053](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS13-053) [KB2850851] [win32k.sys] (XP/Vista/2003/2008/Win 7) - [MS13-046](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS13-046) [KB2840221] [dxgkrnl.sys] (Vista/2003/2008/2012/7) - [MS13-005](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS13-005) [KB2778930] [커널 모드 드라이버] (2003/2008/2012/Win7/8) - [MS12-042](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS12-042) [KB2972621] [Service Bus] (2008/2012/Win7) - [MS12-020](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS12-020) [KB2671387] [RDP] (2003/2008/7/XP) - [MS11-080](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS11-080) [KB2592799] [AFD.sys] (2003/XP) - [MS11-062](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS11-062) [KB2566454] [NDISTAPI] (2003/XP) - [MS11-046](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS11-046) [KB2503665] [AFD.sys] (2003/2008/7/XP) - [MS11-011](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS11-011) [KB2393802] [커널 드라이버] (2003/2008/7/XP/Vista) - [MS10-092](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS10-092) [KB2305420] [작업 스케줄러] (2008/7) - [MS10-065](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS10-065) [KB2267960] [FastCGI] (IIS 5.1, 6.0, 7.0, and 7.5) - [MS10-059](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS10-059) [KB982799] [ACL-Churraskito] (2008/7/Vista) - [MS10-048](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS10-048) [KB2160329] [win32k.sys] (XP SP2 & SP3/2003 SP2/Vista SP1 & SP2/2008 Gold & SP2 & R2/Win7) - [MS10-015](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS10-015) [KB977165] [KiTrap0D] (2003/2008/7/XP) - [MS10-012](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS10-012) [KB971468] [SMB Client Trans2 스택 오버플로] (Windows 7/2008R2) - [MS09-050](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS09-050) [KB975517] [원격 코드 실행] (2008/Vista) - [MS09-020](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS09-020) [KB970483] [IIS 6.0] (IIS 5.1 and 6.0) - [MS09-012](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS09-012) [KB959454] [Chimichurri] (Vista/Win7/2008/Vista) - [MS08-068](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS08-068) [KB957097] [원격 코드 실행] (2000/XP) - [MS08-067](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS08-067) [KB958644] [원격 코드 실행] (Windows 2000/XP/Server 2003/Vista/Server 2008) - [MS08-066](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS08-066) [KB956803] [AFD.sys] (Windows 2000/XP/Server 2003) - [MS08-025](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS08-025) [KB941693] [Win32.sys] (XP/2003/2008/Vista) - [MS06-040](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS06-040) [KB921883] [원격 코드 실행] (2003/XP/2000) - [MS05-039](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS05-039) [KB899588] [PnP 서비스] (Win 9X/ME/NT/2000/XP/2003) - [MS03-026](https://github.com/secwiki/windows-kernel-exploits/blob/master/MS03-026) [KB823980] [RPC 인터페이스 버퍼 오버런] (/NT/2000/XP/2003) ### 도구 - [누락된 패치 감지](https://github.com/secwiki/windows-kernel-exploits/blob/master/win-exp-suggester) [@GDSSecurity](https://github.com/GDSSecurity/Windows-Exploit-Suggester) ### 프로젝트 유지 + **ourren**(시나 웨이보 <a href="http://weibo.com/codesec">@ourren</a>) + **hx**(시나 웨이보 <a href="http://weibo.com/Hexajon">@hx</a>) + **Bearcat**(github <a href="https://github.com/iBearcat">@Bearcat</a>) + **CaledoniaProject**(github <a href="https://github.com/CaledoniaProject">@CaledoniaProject</a>) ### 면책 조항 불법적인 용도로 사용하지 마십시오. 그로 인한 심각한 결과는 본 프로젝트와 무관합니다. ### 참고 링크 - [Windows Kernel Exploits](https://pentestlab.blog/2017/04/24/windows-kernel-exploits/) - [Windows-Exploit-Suggester](https://github.com/GDSSecurity/Windows-Exploit-Suggester) - [WindowsExploits](https://github.com/abatchy17/WindowsExploits) - [Privilege-Escalation](https://github.com/AusJock/Privilege-Escalation) - [Windows Privilege Escalation Fundamentals](http://fuzzysecurity.com/tutorials/16.html) - [brianwrf/WinSystemHelper](https://github.com/brianwrf/WinSystemHelper) - [Vulners](https://vulners.com/landing) - [Windows Exploits](https://github.com/WindowsExploits/Exploits) ### 재배포 출처 표시: https://github.com/SecWiki/windows-kernel-exploits ### 보완 제안 누락된 내용이 있으면 자유롭게 추가해 주세요. [[email protected]](https://github.com/secwiki/windows-kernel-exploits/blob/master/git_man%40outlook.com) ©<a href="https://www.sec-wiki.com" target="_blank">SecWiki</a> 2017