Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2021-31166 — Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely. | Kitploit
工具/GitHubGitHub/0vercl0k/cve-2021-31166
Vulnerability AnalysisExploitationWeb SecurityRemote Access ToolBinary ExploitationArchived
GitHub0vercl0k/cve-2021-31166

CVE-2021-31166

Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.

查看仓库
8271355年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2021-31166: HTTP协议栈远程代码执行漏洞

本内容是关于 CVE-2021-31166(“HTTP协议栈远程代码执行漏洞”)的概念验证,该漏洞是 http.sys 中的释放后使用(use-after-free)类型问题,微软于2021年5月发布了补丁。根据这条 推文,该漏洞由 @_mxms 和 @fzzyhd1 发现。

trigger

漏洞本身发生在 http!UlpParseContentCoding 函数中,该函数创建了一个局部 LIST_ENTRY 并向其中追加条目。完成后,它会将其移动到 Request 结构体中,但并未将局部列表置为 NULL。问题在于,攻击者可以触发某条代码路径,该路径会释放局部列表中的所有条目,导致这些条目在 Request 对象中成为悬空指针。

rel04vsrel05

以下是崩溃检查(bugcheck)信息:

root@kitploit:~
KDTARGET: Refreshing KD connection

*** Fatal System Error: 0x00000139
                       (0x0000000000000003,0xFFFFF90EA867EE40,0xFFFFF90EA867ED98,0x0000000000000000)

Break instruction exception - code 80000003 (first chance)

A fatal system error has occurred.
Debugger entered on first try; Bugcheck callbacks have not been invoked.

A fatal system error has occurred.

nt!DbgBreakPointWithStatus:
fffff804`19410c50 cc              int     3

kd> kp
 # Child-SP          RetAddr               Call Site
00 fffff90e`a867e368 fffff804`19525382     nt!DbgBreakPointWithStatus
01 fffff90e`a867e370 fffff804`19524966     nt!KiBugCheckDebugBreak+0x12
02 fffff90e`a867e3d0 fffff804`19408eb7     nt!KeBugCheck2+0x946
03 fffff90e`a867eae0 fffff804`1941ad69     nt!KeBugCheckEx+0x107
04 fffff90e`a867eb20 fffff804`1941b190     nt!KiBugCheckDispatch+0x69
05 fffff90e`a867ec60 fffff804`19419523     nt!KiFastFailDispatch+0xd0
06 fffff90e`a867ee40 fffff804`1db3f677     nt!KiRaiseSecurityCheckFailure+0x323
07 fffff90e`a867efd0 fffff804`1daf6c05     HTTP!UlFreeUnknownCodingList+0x63
08 fffff90e`a867f000 fffff804`1dacd201     HTTP!UlpParseAcceptEncoding+0x299c5
09 fffff90e`a867f0f0 fffff804`1daa93d8     HTTP!UlAcceptEncodingHeaderHandler+0x51
0a fffff90e`a867f140 fffff804`1daa8ab7     HTTP!UlParseHeader+0x218
0b fffff90e`a867f240 fffff804`1da04c5f     HTTP!UlParseHttp+0xac7
0c fffff90e`a867f3a0 fffff804`1da0490a     HTTP!UlpParseNextRequest+0x1ff
0d fffff90e`a867f4a0 fffff804`1daa48c2     HTTP!UlpHandleRequest+0x1aa
0e fffff90e`a867f540 fffff804`1932ae85     HTTP!UlpThreadPoolWorker+0x112
0f fffff90e`a867f5d0 fffff804`19410408     nt!PspSystemThreadStartup+0x55
10 fffff90e`a867f620 00000000`00000000     nt!KiStartSystemThread+0x28

kd> !analyze -v
[...]
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure.  The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: fffff90ea867ee40, Address of the trap frame for the exception that caused the BugCheck
Arg3: fffff90ea867ed98, Address of the exception record for the exception that caused the BugCheck
Arg4: 0000000000000000, Reserved

常见问题解答

问:Windows 远程管理 (WinRM) 是否受此漏洞影响?

是的(感谢 @JimDinMN 分享 他的实验)。

问:Web Services on Devices (WSDAPI) 是否受此漏洞影响?

是的(感谢 @HenkPoley 分享 他的结果)。

问:受影响的 Windows 版本有哪些?

根据 微软的文档,受影响的平台如下:

  • Windows Server, version 2004 (或 20H1) (Server Core 安装),
  • Windows 10 Version 2004 (或 20H1) for ARM64/x64/32-bit Systems,
  • Windows Server, version 20H2 (Server Core 安装),
  • Windows 10 Version 20H2 for ARM64/x64/32-bit Systems。
下载工具