Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2024-38143 PoC — Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability

Source
Associated Vulnerability
Title:Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability (CVE-2024-38143)
Description:Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability
Description
Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability
Readme
# CVE-2024-38143
Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability<br>
Successful exploitation can lead to possible escalation to NT AUTHORITY\SYSTEM
# Background
While on a client engagement, I had to test a physical laptop and for some reason, stumbled upon this [article](https://shenaniganslabs.io/2021/04/13/Airstrike.html) by Matthew Johnson, which was his resultant discovery of CVE-2021-28316. I wondered if it could be possible to modify and perform a similar type of attack, but what I discovered was that it actually just...worked right out of the gate. My client at the time basically said, "Wait this isn't supposed to work against a patched device". He wasn't wrong, this was allegedly [patched](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-28316) in April of 2021. It obviously was not, thus, an unfixed vulnerability. 

There's not much of a point in replicating the PoC steps once again, because in all fairness - Matthew Johnson found this bug and all I did was discover that Microsoft's previous patch was unsuccessful. If you're interested in setting up this attack, [use this guide](https://shenaniganslabs.io/2021/04/13/Airstrike.html), and remember that you'll need an unpatched version of Windows.
# Proof of Concept Video
https://github.com/user-attachments/assets/6bf025e7-3a53-40ce-a4a5-5886423e2839

File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →