Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2020-24955 PoC — SUPERAntiSyware Professional 安全漏洞

Source
Associated Vulnerability
Title:SUPERAntiSyware Professional 安全漏洞 (CVE-2020-24955)
Description:SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a malicious DLL from quarantine into the system32 folder via an NTFS directory junction, as demonstrated by a crafted ualapi.dll file that is detected as malware.
Description
SUPERAntiSyware Professional X Trial <= 10.0.1206 Local Privilege Escalation
Readme
# CVE-2020-24955
### **SUPERAntiSpyware Professional X Trial <= 10.0.1206 Local Privilege Escalation**

SUPERAntiSpyware Professional X Trial versions prior to 10.0.1206 are vulnerable to local privilege escalation because it allows unprivileged users to restore quarantined files to a privileged location through a NTFS directory junction. 

**Home Page:** https://www.superantispyware.com/

**Proof of Concept**
1. Place a dll payload in an empty folder
2. Scan the payload with the  SUPERAntiSpyware Professional X Trial in order to get it detected. 
3. Once it is detected and moved to quarantine, create a NTFS directory junction.
4. Restore the payload and reboot the system.

**Full PoC video:** https://www.youtube.com/watch?v=jdcqbev-H5I

**Timeline:**
* **16-07-2020** - Vulnerability discovered 
* **16-07-2020** - Notified the vendor via support form (vendor did not response)
* **19-07-2020** - Notified the vendor via email (vendor did not response)
* **25-07-2020** - Vulnerability report to CERT/CC (VRF#20-07-GBPVY)
* **25-08-2020** - Vulnerability Disclosed
* **01-09-2020** - CVE Assigned

**References:**
https://bogner.sh/2017/11/avgater-getting-local-admin-by-abusing-the-anti-virus-quarantine/
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →