|
@layle_ctf | |||||
|
Ladies and gentlemen, I present you a working Remote Code Execution (RCE) exploit for the Remote Desktop Gateway (CVE-2020-0609 & CVE-2020-0610). Accidentally followed a few rabbit holes but got it to work! Time to write a blog post ;)
Don't forget to patch! pic.twitter.com/FekupjS6qG
|
||||||
|
||||||
|
Luca Marcelli
@layle_ctf
|
26. sij |
|
If installing the update is not an option you should apply other measurements such as disabling UDP traffic. I'll wait a bit until people had enough time to patch before releasing this to the public :)
|
||
|
|
||
|
Luca Marcelli
@layle_ctf
|
26. sij |
|
Also, shoutout to @ollypwn for helping me out with my Denial of Service script and my vulnerability scanner!
|
||
|
|
||
|
Luca Marcelli
@layle_ctf
|
28. sij |
|
I've been talking to a few professionals that are more experienced than me and I came to the conclusion that it's the best if I keep the source code private for the time being. I surely don't want to put any companies at risk!
|
||
|
|
||
|
ɯɹoʇsuoı
@ionstorm
|
31. sij |
|
hey @layle_ctf whats the parent process that shells are popped from? svchost?
|
||
|
|
||
|
Luca Marcelli
@layle_ctf
|
31. sij |
|
I haven't tried to pop a shell and I'm not really working on this anymore either. The DLL is mapped into svchost.exe, which runs as network service account and doesn't have access to the filesystem which is why I don't think a shell would be easy to get. 1/2
|
||
|
|
||
|
ɯɹoʇsuoı
@ionstorm
|
26. sij |
|
Nice work
|
||
|
|
||
|
Luca Marcelli
@layle_ctf
|
26. sij |
|
Thank you! I was really sick the past few days and I didn't sleep to get this to work, was totally worth it though!
|
||
|
|
||
|
BenBE
@BenBE1987
|
26. sij |
|
It ain't RCE if it doesn't start calc.exe … #SCNR
Great work!
|
||
|
|
||
|
Luca Marcelli
@layle_ctf
|
26. sij |
|
Will post a video of a calc.exe pop later ;)
|
||
|
|
||
|
PO3T
@PO3T1985
|
26. sij |
|
Isn't this the same as @ollypwn BlueGate exploit? (reported 2 days ago)
github.com/ollypwn/BlueGa…
|
||
|
|
||
|
Luca Marcelli
@layle_ctf
|
26. sij |
|
He made a Denial of Service exploit and a vulnerability checker but couldn't achieve RCE yet.
|
||
|
|
||