WebDAV Local Elevation of Privilege Vulnerability (CVE-2016-0051) POC & EXP
Vulnerability Information
This vulnerability exists in Microsoft Web Distributed creation and Version Management (WebDAV). If the Microsoft Web Distributed creation and Version Management (WebDAV) Client verifies incorrect input, the privilege escalation vulnerability exists. Successful exploits allow attackers to execute arbitrary code with elevated privileges.
To exploit this vulnerability, attackers must first log on to the system. Then, attackers can run an application specially designed to exploit this vulnerability to control the affected system.
Workstations and servers are most vulnerable to this attack. This security update program fixes this vulnerability by correcting WebDAV verification input.
Vulnerability impact Scope
Windows Vista SP2 x86 & x64 (Privilege Escalation)
Windows Server 2008 SP2 x86 & x64 (Privilege Escalation)
Windows Server 2008 R2 SP1 x64 (Privilege Escalation)
Windows 7 SP1 x86 & x64 (Privilege Escalation)
Windows 8.1x86 & x64 (DOS)
Windows Server 2012 (DOS)
Windows Server 2012 R2 (DOS)
Windows RT 8.1 (DOS)
Windows 10 (DOS)
POC & EXP
The vulnerability author released the POC for the blue screen and the Elevation of Privilege EXP for the 32-bit win7 system.
Address:
Https://github.com/koczkatamas/CVE-2016-0051
Demonstration of Local Elevation of Privilege for Windows 7 SP1 x86:
Windows 10 x64 blue screen Demonstration:
Repair suggestions
Automatically download and install the update program through the windows Update Program. Or go to the Microsoft Security Center to obtain an independent update package.