在 win32k 中存在一个漏洞,攻击者可以利用该漏洞将权限提升至 NT AUTHORITY\SYSTEM。该缺陷存在于窗口的 WndExtra 字段的处理方式中,该字段可能被当作偏移量来处理,尽管其内容由攻击者控制的值填充。这可用于实现越界写入操作,最终导致权限提升。该漏洞最初被标识为 CVE-2021-1732,并于 2021 年 2 月 9 日由 Microsoft 修复。2022 年初。
CVE-2021-1732.exe "the-command"
"the-command" 使用命令行界面(CLI)支持的所有命令,例如 "whoami"
Download Exploit Script for CVE-2021-3560 Here

Windows Server, version 20H2 (Server Core 安装), Windows 10 Version 20H2, Windows Server, version 2004 (Server Core 安装), Windows 10 Version 2004, Windows Server, version 1909 (Server Core 安装), Windows 10 Version 1909, Windows Server 2019 (Server Core 安装), Windows Server 2019, Windows 10 Version 1809
⚠️ 在系统上运行此漏洞利用程序时请小心。