
Kingsoft Antivirus KWatch Driver 버전 2009.3.17.77의 로컬 EoP 취약점에 대한 수년 된 익스플로잇입니다.
Kingsoft Antivirus KWatch 드라이버 버전 2009.3.17.77의 로컬 EoP 취약점을 악용하는 수년 전의 익스플로잇입니다.
저는 2014년 1월에 이 이슈를 보고했고, 8년 이상이 지나서야 CVE를 통보받았습니다. 제 예전 코드를 발견하게 된 점과 그렇게 오랜 시간이 걸렸다는 점이 재미있어서 이걸 업로드하기로 결정했습니다.
따라서 새로운 CVE 번호에도 불구하고 이것은 새로운 취약점이 아닐 것입니다. -- 빠른 검색 결과 이미 동일해 보이는 취약점에 대한 보고가 여러 건 있었기 때문입니다.
IPA가 제 역할을 다해 주고 기분 좋은 하루를 만들어 준 것에 여전히 감사합니다.
취약한 파일은 ffdedbaeccbcf0b697675b24ca313cbb8e1c9ba1bd2f0a0b58a2d6a04a038479로 보입니다.
//
// Exploit for Kingsoft Antivirus KWatch Driver (KWatch3.sys)
// Target File Version: 2009.3.17.77
// Affected Product: Kingsoft Internet Security 9 Plus
//
/*
------------------------------------------------------------------------------
Shellcode is located at 7E7E7E7E.
The device was opened as 00000020.
Shellcode was executed.
The SYSTEM shell was launched.
This process will be suspended for ever.
------------------------------------------------------------------------------
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\Users\user\Desktop>whoami
nt authority\system
------------------------------------------------------------------------------
*/