Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-24955 PoC — SUPERAntiSyware Professional 安全漏洞

Source
Associated Vulnerability
Title:SUPERAntiSyware Professional 安全漏洞 (CVE-2020-24955)
Description:SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a malicious DLL from quarantine into the system32 folder via an NTFS directory junction, as demonstrated by a crafted ualapi.dll file that is detected as malware.
Description
SUPERAntiSyware Professional X Trial <= 10.0.1206 Local Privilege Escalation
Readme
# CVE-2020-24955
### **SUPERAntiSpyware Professional X Trial <= 10.0.1206 Local Privilege Escalation**

SUPERAntiSpyware Professional X Trial versions prior to 10.0.1206 are vulnerable to local privilege escalation because it allows unprivileged users to restore quarantined files to a privileged location through a NTFS directory junction. 

**Home Page:** https://www.superantispyware.com/

**Proof of Concept**
1. Place a dll payload in an empty folder
2. Scan the payload with the  SUPERAntiSpyware Professional X Trial in order to get it detected. 
3. Once it is detected and moved to quarantine, create a NTFS directory junction.
4. Restore the payload and reboot the system.

**Full PoC video:** https://www.youtube.com/watch?v=jdcqbev-H5I

**Timeline:**
* **16-07-2020** - Vulnerability discovered 
* **16-07-2020** - Notified the vendor via support form (vendor did not response)
* **19-07-2020** - Notified the vendor via email (vendor did not response)
* **25-07-2020** - Vulnerability report to CERT/CC (VRF#20-07-GBPVY)
* **25-08-2020** - Vulnerability Disclosed
* **01-09-2020** - CVE Assigned

**References:**
https://bogner.sh/2017/11/avgater-getting-local-admin-by-abusing-the-anti-virus-quarantine/
File Snapshot

[4.0K] /data/pocs/e624f90dcfdd874d22f6a571e3e47b0096ac5663 └── [1.2K] README.md 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →