** 설명
- CVE-2021-31166에 대한 PoC: Windows HTTP 프로토콜 스택 원격 코드 실행 취약점
- antx가 2021-09-27에 생성함.
** 세부 정보
- [[./trigger.gif][Poc-Gif]]
** CVE 심각도
- attackComplexity: LOW
- attackVector: NETWORK
- availabilityImpact: HIGH
- confidentialityImpact: HIGH
- integrityImpact: HIGH
- privilegesRequired: NONE
- scope: CHANGED
- userInteraction: NONE
- version: 3.1
- baseScore: 9.8
- baseSeverity: CRITICAL
** 영향
- Windows Server, 버전 2004 (또는 20H1) (Server Core 설치),
- ARM64/x64/32비트 시스템용 Windows 10 버전 2004 (또는 20H1),
- Windows Server, 버전 20H2 (Server Core 설치),
- ARM64/x64/32비트 시스템용 Windows 10 버전 20H2,
- Windows Remote Management (WinRM)
- Web Services on Devices (WSDAPI)
- KB4598481, KB5003173, KB5000736 Windows 시스템 패치가 없거나 시스템 ISO가 2021-05 이전인 경우.
** PoC
- [[./CVE-2021-31166.py][Python-PoC]]
- [[./main.go][Golang-PoC]]
** 참조
- 참조-소스
- [[https://github.com/0vercl0k/CVE-2021-31166][0vercl0k/CVE-2021-31166]]
- 참조-문서
- [[https://www.freebuf.com/vuls/281302.html][CVE-2021-31166 Windows HTTP 프로토콜 스택 원격 코드 실행 취약점 재현]]
- 참조-위험
- [[https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-31166][HTTP 프로토콜 스택 원격 코드 실행 취약점]]
- [[https://nvd.nist.gov/vuln/detail/CVE-2021-31166][NVD]]
- CVE
- [[https://github.com/CVEProject/cvelist/blob/master/2021/31xxx/CVE-2021-31166.json][CVE-2021-31166]]