Subscribe via feed.
Archive for May, 2021

Windows Container Manager Service CmsRpcSrv_CreateContainer Privilege Escalation

Posted by deepcore under exploit (No Respond)

The Container Manager Service accepts an access token provided by the user without verification allowing an arbitrary process to be created with another user identity leading to privilege escalation.

Windows Container Manager Service CmsRpcSrv_MapVirtualDiskToContainer Privilege Escalation

Posted by deepcore under exploit (No Respond)

The Container Manager Service does not impersonate the caller when granting access to virtual disk images leading to privilege escalation.

Windows Container Manager Service Arbitrary Object Directory Creation Privilege Escalation

Posted by deepcore under exploit (No Respond)

The Container Manager Service creates an AppContainer process without impersonating the access token leading to privilege escalation.

ExifTool DjVu ANT Perl Injection

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits a Perl injection vulnerability in the DjVu ANT parsing code of ExifTool versions 7.44 through 12.23 inclusive. The injection is used to execute a shell command using Perl backticks. The DjVu image can be embedded in a wrapper image using the HasselbladExif EXIF field.

Windows Container Manager Service CmsRpcSrv_MapNamedPipeToContainer Privilege Escalation

Posted by deepcore under exploit (No Respond)

The Container Manager Service does not configure STORVSP correctly when opening mapped named pipes leading to privilege escalation.

[local] Firefox 72 IonMonkey – JIT Type Confusion

Posted by deepcore under Security (No Respond)

Firefox 72 IonMonkey – JIT Type Confusion

Tags: ,

[local] Microsoft Internet Explorer 8/11 and WPAD service 'Jscript.dll' – Use-After-Free

Posted by deepcore under Security (No Respond)

Microsoft Internet Explorer 8/11 and WPAD service ‘Jscript.dll’ – Use-After-Free

Tags: ,

[webapps] ZeroShell 3.9.0 – Remote Command Execution

Posted by deepcore under Security (No Respond)

ZeroShell 3.9.0 – Remote Command Execution

Tags: ,

[webapps] Dental Clinic Appointment Reservation System 1.0 – Authentication Bypass (SQLi)

Posted by deepcore under Security (No Respond)

Dental Clinic Appointment Reservation System 1.0 – Authentication Bypass (SQLi)

Tags: ,

[webapps] Dental Clinic Appointment Reservation System 1.0 – 'date' UNION based SQL Injection (Authenticated)

Posted by deepcore under Security (No Respond)

Dental Clinic Appointment Reservation System 1.0 – ‘date’ UNION based SQL Injection (Authenticated)

Tags: ,