Exploiting Cve-2015-2509/ms15-100:windows Media Center could allow remote code executiontrend Micro Blog about it few D Ays ago. This vulnerability was related to Hacking Team leaked email addresses. The issue is so trival that exploitation is a piece of cake.
source:https://technet.microsoft.com/en-us/library/security/ms15-100
Based on POC and description we just need to create a simple MCL file contains our executable path and preso it works.
The caveat for this attack is so you cannot passed a argument such as cmd.exe/c ipconfig in the MCL file. However we can execute our payload externally via UNC PATH provided by a simple SMB Server. The steps required.
1. Generate Evil payload exe
2. Setup a SMB Listener
3. Create MCL file, points to evil payload.
4. Profits.
I use Impacket SMB Server to simulate the steps above. If you is a bit creative, we can use the DLL hijacking Method to cloak our payload.
Better patch it up fast.
Exploiting Cve-2015-2509/ms15-100:windows Media Center could allow remote code execution