
initial exploit for CVE-2019-0708, BlueKeep CVE-2019-0708 BlueKeep RDP Remote Windows Kernel Use After Free The RDP termdd.sys driver improperly handles binds to internal-only channel MS_T120, allowing a malformed Disconnect Provider Indication message to cause use-after-free. With a controllable data/size remote nonpaged pool spray, an indirect call gadget of the freed channel is used to achieve arbitrary code execution.
CVE-2019-0708 的初始利用程序,BlueKeep CVE-2019-0708 BlueKeep RDP 远程 Windows 内核释放后使用
RDP 的 termdd.sys 驱动程序不当处理对内部专用通道 MS_T120 的绑定,导致格式错误的 Disconnect Provider Indication 消息可能引发释放后使用。通过可控数据/大小的远程非分页池喷射,利用释放通道的间接调用 gadget 实现任意代码执行。
该利用程序应能针对以下 Windows 系统中存在漏洞的 RDP 服务工作:
本利用模块当前针对以下运行于多个虚拟化和物理目标上的 Windows 系统:
msfconsoleuse exploit/windows/rdp/cve_2019_0708_bluekeep_rceset RHOSTS 设置为 Windows 7/2008 x64set TARGETset PAYLOADexploit