WebDAV Local Elevation of Privilege Vulnerability (CVE-2016-0051) POC & amp; EXP

Source: Internet
Author: User

WebDAV Local Elevation of Privilege Vulnerability (CVE-2016-0051) POC & EXP

Vulnerability Information

This vulnerability exists in Microsoft Web Distributed creation and Version Management (WebDAV). If the Microsoft Web Distributed creation and Version Management (WebDAV) Client verifies incorrect input, the privilege escalation vulnerability exists. Successful exploits allow attackers to execute arbitrary code with elevated privileges.

To exploit this vulnerability, attackers must first log on to the system. Then, attackers can run an application specially designed to exploit this vulnerability to control the affected system.

Workstations and servers are most vulnerable to this attack. This security update program fixes this vulnerability by correcting WebDAV verification input.

Vulnerability impact Scope

Windows Vista SP2 x86 & x64 (Privilege Escalation)

Windows Server 2008 SP2 x86 & x64 (Privilege Escalation)

Windows Server 2008 R2 SP1 x64 (Privilege Escalation)

Windows 7 SP1 x86 & x64 (Privilege Escalation)

Windows 8.1x86 & x64 (DOS)

Windows Server 2012 (DOS)

Windows Server 2012 R2 (DOS)

Windows RT 8.1 (DOS)

Windows 10 (DOS)

POC & EXP

The vulnerability author released the POC for the blue screen and the Elevation of Privilege EXP for the 32-bit win7 system.

Address:

Https://github.com/koczkatamas/CVE-2016-0051

Demonstration of Local Elevation of Privilege for Windows 7 SP1 x86:

Windows 10 x64 blue screen Demonstration:

Repair suggestions

Automatically download and install the update program through the windows Update Program. Or go to the Microsoft Security Center to obtain an independent update package.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.