mstlsap.dll / tlslicense.dll 暴露的 RPC over TCP 端点发送特制的 RPC 数据包,触发堆缓冲区溢出,从而以 SYSTEM 权限执行任意代码。远程桌面许可服务监听在 RPC 动态端点上(通常端口为 49664–49681),可通过 TCP 端口 135(RPC 端点映射器)访问。该漏洞位于许可服务堆内存管理中的 LicensingSendResponse 或相关 RPC 接口处理函数。通过发送一个包含超大或畸形 LicensingBinary 结构的特制许可协议请求,服务会执行不安全的 memcpy 操作,将数据复制到大小不足的堆缓冲区,从而破坏相邻堆元数据并实现代码执行。
关键要点:
| 产品 | 影响 |
|---|---|
| Windows Server 2008 R2(所有版本) | RCE |
| Windows Server 2012 / 2012 R2 | RCE |
| Windows Server 2016 | RCE |
| Windows Server 2019 | RCE |
| Windows Server 2022 | RCE |
| Windows Server 2025 | RCE |
早期版本(Windows 2000 Server、Server 2003、Server 2008)如果在启用了 RDL 服务的情况下也可能受影响。
net start "Remote Desktop Licensing"netstat -an | findstr LISTENINGpython exploit.py --target <TARGET_IP>
tlslicense.dll 服务的崩溃或系统崩溃(根据堆破坏严重程度可能出现蓝屏)。svchost.exe 进程,并观察访问冲突。本目录中的 exploit.py 脚本包含 MadLicense 攻击的复现。它通过 RPC over TCP 连接到目标 RDL 服务,构造一个包含超大二进制块的畸形许可请求,并触发堆缓冲区溢出。
sc stop "Remote Desktop Licensing"
sc config "Remote Desktop Licensing" start= disabled