Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2019-0708 — initial exploit for CVE-2019-0708, BlueKeep CVE-2019-0708 BlueKeep RDP Remote Windows Kernel Use After Free The RDP termdd.sys driver improperly handles binds to internal-only channel MS_T120, allowing a malformed Disconnect Provider Indication message to cause use-after-free. With a controllable data/size remote nonpaged pool spray, an indirect call gadget of the freed channel is used to achieve arbitrary code execution. | Kitploit
工具/GitHubGitHub/wqsemc/cve-2019-0708
Exploit FrameworksVulnerability AnalysisExploitationPenetration TestingRemote Access ToolPayload Development
GitHubwqsemc/cve-2019-0708

CVE-2019-0708

查看仓库

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →

关于

initial exploit for CVE-2019-0708, BlueKeep CVE-2019-0708 BlueKeep RDP Remote Windows Kernel Use After Free The RDP termdd.sys driver improperly handles binds to internal-only channel MS_T120, allowing a malformed Disconnect Provider Indication message to cause use-after-free. With a controllable data/size remote nonpaged pool spray, an indirect call gadget of the freed channel is used to achieve arbitrary code execution.

分享
网站
12156年前尚未审核

CVE-2019-0708

CVE-2019-0708 的初始利用程序,BlueKeep CVE-2019-0708 BlueKeep RDP 远程 Windows 内核释放后使用

RDP 的 termdd.sys 驱动程序不当处理对内部专用通道 MS_T120 的绑定,导致格式错误的 Disconnect Provider Indication 消息可能引发释放后使用。通过可控数据/大小的远程非分页池喷射,利用释放通道的间接调用 gadget 实现任意代码执行。

受影响的应用

该利用程序应能针对以下 Windows 系统中存在漏洞的 RDP 服务工作:

  • Windows 2000 x86(所有 Service Pack)
  • Windows XP x86(所有 Service Pack)
  • Windows 2003 x86(所有 Service Pack)
  • Windows 7 x86(所有 Service Pack)
  • Windows 7 x64(所有 Service Pack)
  • Windows 2008 R2 x64(所有 Service Pack)

本利用模块当前针对以下运行于多个虚拟化和物理目标上的 Windows 系统:

  • Windows 7 x64(所有 Service Pack)
  • Windows 2008 R2 x64(所有 Service Pack)

验证步骤

  • 启动 msfconsole
  • use exploit/windows/rdp/cve_2019_0708_bluekeep_rce
  • set RHOSTS 设置为 Windows 7/2008 x64
  • 根据目标主机特性 set TARGET
  • set PAYLOAD
  • exploit
  • 验证 获取到 shell
  • 验证 系统未崩溃

选项

下载工具