Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
POC-CVE-2026-56164-exploit — CVE-2026-56164 是一个影响本地部署的 Microsoft SharePoint Server 的严重缺失身份验证漏洞。它允许未经认证的远程攻击者通过网络提升权限。 | Kitploit
工具/GitHubGitHub/sam00/poc-cve-2026-56164-exploit
身份验证与授权权限提升漏洞扫描器Payload生成漏洞利用Web应用程序漏洞利用信息收集渗透测试
GitHubsam00/poc-cve-2026-56164-exploit

POC-CVE-2026-56164-exploit

CVE-2026-56164 是一个影响本地部署的 Microsoft SharePoint Server 的严重缺失身份验证漏洞。它允许未经认证的远程攻击者通过网络提升权限。

查看仓库
2151个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2026-56164 — Microsoft SharePoint Server 身份验证绕过漏洞利用工具

严重(CVSS 9.8) — 在 Microsoft SharePoint Server 中,未经身份验证即可将权限提升至场管理员

目录

  • 概述
  • 漏洞详情
  • 受影响版本
  • 架构图
  • 项目结构
  • 安装
  • 扫描器使用 — 分步指南
  • 漏洞利用工具使用 — 分步指南
  • 载荷设计
  • 缓解措施
  • 免责声明

概述

CVE-2026-56164 是 Microsoft SharePoint Server 中的一个严重缺失身份验证漏洞,允许未经过身份验证的远程攻击者将权限提升至场管理员级别。该漏洞位于 Microsoft.Office.Server.UserProfiles 程序集中,该程序集在 /_vti_bin/client.svc/ProcessQuery 处处理 SOAP 请求。

通过故意省略 X-RequestDigest 标头并提供特定的路由标头,易受攻击的服务器会回退到提升的安全上下文,而不是拒绝未经过身份验证的请求。这允许匿名攻击者枚举网站集、用户、场配置,添加管理员以及执行命令。

CISA KEV:由于在野积极利用,此漏洞已列入 CISA 的已知被利用漏洞目录。


漏洞详情

字段值
CVE IDCVE-2026-56164
严重性严重
CVSS 3.19.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CWECWE-306:关键功能缺少身份验证
影响未经身份验证即可将权限提升至场管理员
利用状态积极利用(CISA KEV)
MITRE ATT&CKT1190(利用面向公众的应用程序)

根本原因

Microsoft.Office.Server.UserProfiles 处理程序在 /_vti_bin/client.svc/ProcessQuery 处处理 SOAP 请求。正常操作下,SharePoint 会验证 X-RequestDigest 标头以确认身份验证上下文。然而,存在一个验证绕过:

  1. 如果 X-RequestDigest 不存在且存在特定的路由标头
  2. 系统会评估路由参数并回退到高特权默认状态
  3. 请求会以系统级凭据而非调用方的安全上下文进行处理

易受攻击的代码路径

// Vulnerable: If digest is missing, handler checks routing headers
if (string.IsNullOrEmpty(digest) && CheckSpecialRoutingHeaders(context)) {
    // Bypasses standard identity validation → elevated admin session
    InitializeElevatedSecurityContext(context);
} else {
    ValidateRequestDigest(digest);  // Normal path
}

已修补的代码

// Patched: Digest validation is unconditional
if (string.IsNullOrEmpty(digest)) {
    context.Response.StatusCode = 401;
    throw new UnauthorizedAccessException("Missing request digest.");
}
ValidateRequestDigest(digest);
InitializeStandardSecurityContext(context);

公告参考

  • MSRC:https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164
  • NVD:https://nvd.nist.gov/vuln/detail/CVE-2026-56164
  • CISA KEV:https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56164

受影响版本

产品受影响版本已修补版本
SharePoint Enterprise Server 2016修补前所有 16.0.x16.0.5561.1001
SharePoint Server 2019修补前所有 16.0.x16.0.10417.20175
SharePoint Server Subscription Edition修补前所有 16.0.x16.0.19725.20434

不受影响:SharePoint Online(Microsoft 365)


架构图

系统架构

┌─────────────────────────────────────────────────────────────────────┐
│                   CVE-2026-56164 Exploit Toolkit                     │
├─────────────────────────────────────────────────────────────────────┤
│                                                                      │
│  ┌────────────┐     ┌─────────────────┐     ┌────────────────────┐  │
│  │  scan.py   │────▶│  HTTP Fingerprint│     │  payload_gen.py    │  │
│  │  Scanner   │     │  + Version Check │     │                    │  │
│  └────────────┘     └─────────────────┘     │  ┌──────────────┐  │  │
│         │                                   │  │ CSOM Payloads│  │  │
│         │  Reports:                         │  │ (detection,  │  │  │
│         │  • SharePoint detected?           │  │  enum,       │  │  │
│         │  • Server version                 │  │  elevate,    │  │  │
│         │  • Vulnerable?                    │  │  execute)    │  │  │
│         │  • Auth bypass confirmed?         │  └──────────────┘  │  │
│         ▼                                   │  ┌──────────────┐  │  │
│  ┌────────────┐     ┌─────────────────┐     │  │ SOAP Payloads│  │  │
│  │ exploit.py │────▶│  HTTP Request   │     │  │ (admin, exec)│  │  │
│  │  Exploit   │     │  Delivery       │     │  └──────────────┘  │  │
│  └────────────┘     └─────────────────┘     │  ┌──────────────┐  │  │
│         │                                   │  │ Bypass       │  │  │
│         │  ┌──────────────────────┐         │  │ Headers      │  │  │
│         ├─▶│ MODE: detect         │         │  │ (routing)    │  │  │
│         │  │ Safe, non-intrusive  │         │  └──────────────┘  │  │
│         │  └──────────────────────┘         │  ┌──────────────┐  │  │
│         │  ┌──────────────────────┐         │  │ HTTP Request │  │  │
│         ├─▶│ MODE: enumerate      │         │  │ Builder      │  │  │
│         │  │ Sites, users, config │         │  └──────────────┘  │  │
│         │  └──────────────────────┘         └────────────────────┘  │
│         │  ┌──────────────────────┐                                 │
│         ├─▶│ MODE: elevate        │     ┌──────────────────────┐    │
│         │  │ Add site/farm admin  │     │ Target SharePoint    │    │
│         │  └──────────────────────┘     │ /_vti_bin/client.svc │    │
│         │  ┌──────────────────────┐     │ /_vti_bin/SPAdmin    │    │
│         └─▶│ MODE: execute        │     └──────────────────────┘    │
│            │ System commands      │                                 │
│            └──────────────────────┘                                 │
│         │  ┌──────────────────────┐                                 │
│         └─▶│ MODE: full           │  detect→enum→elevate→execute    │
│            └──────────────────────┘                                 │
└─────────────────────────────────────────────────────────────────────┘

扫描器流程

┌─────────────┐
│  Start Scan │
└──────┬──────┘
       │
       ▼
┌──────────────────┐     No     ┌─────────────┐
│ Target reachable?│──────────▶│  Skip       │
└──────┬───────────┘            └─────────────┘
       │ Yes
       ▼
┌──────────────────┐
│ Send HTTP GET    │
│ to common ports  │
│ (443,80,8080,    │
│  8443)           │
└──────┬───────────┘
       │
       ▼
┌──────────────────┐     No     ┌─────────────┐
│ SharePoint       │──────────▶│ Not SP      │
│ fingerprint?     │            └─────────────┘
│ (MSST header,    │
│  _vti_bin,       │
│  suitebar, etc.) │
└──────┬───────────┘
       │ Yes
       ▼
┌──────────────────┐
│ Extract version  │
│ from MSST header │
│ / response body  │
└──────┬───────────┘
       │
       ▼
┌──────────────────┐     No     ┌─────────────┐
│ Version in       │──────────▶│ Not         │
│ vulnerable       │            │ vulnerable  │
│ range?           │            └─────────────┘
└──────┬───────────┘
       │ Yes
       ▼
┌──────────────────┐
│ Test auth bypass │
│ (CSOM req w/o    │
│  digest + bypass │
│  headers)        │
└──────┬───────────┘
       │
       ▼
┌──────────────────┐
│ Report:          │
│ • VULNERABLE     │
│ • Version        │
│ • Bypass status  │
│ • SSL cert info  │
└──────────────────┘

利用流程(完整攻击链)

下载工具