域渗透历史漏洞汇总
2022-4-14 09:15:0 Author: mp.weixin.qq.com(查看原文) 阅读量:38 收藏

文章来源 :Leticia

原文链接:

http://uuzdaisuki.com/2022/01/20/%E5%9F%9F%E6%B8%97%E9%80%8F%E5%8E%86%E5%8F%B2%E6%BC%8F%E6%B4%9E%E6%B1%87%E6%80%BB/#CVE-2020-16875

MS14-068(CVE-2014-6324)

Kerberos 校验和漏洞

 https://nvd.nist.gov/vuln/detail/CVE-2014-6324

EXP/POC:

 https://github.com/abatchy17/WindowsExploits/tree/master/MS14-068

CVE-2020-1472

Netlogon特权提升漏洞

 https://nvd.nist.gov/vuln/detail/CVE-2020-1472

EXP/POC:

 https://github.com/blackarrowsec/redteam-research/tree/master/CVE-2020-1472

CVE-2021-42287&42278

Windows域服务权限提升漏洞

 https://nvd.nist.gov/vuln/detail/CVE-2021-42287 https://nvd.nist.gov/vuln/detail/CVE-2021-42278

EXP/POC:

 https://github.com/WazeHell/sam-the-admin https://github.com/cube0x0/noPac

CVE-2019-1040

Microsoft Windows NTLM认证漏洞

 https://nvd.nist.gov/vuln/detail/CVE-2019-1040 https://paper.seebug.org/962/

EXP/POC:

 https://github.com/Ridter/CVE-2019-1040

CVE-2018-8581

Microsoft Exchange任意用户伪造漏洞

 https://nvd.nist.gov/vuln/detail/CVE-2018-8581

EXP/POC:

 https://github.com/Ridter/Exchange2domain

CVE-2020-0688

Microsoft Exchange 反序列化RCE

 https://nvd.nist.gov/vuln/detail/CVE-2020-0688

EXP/POC:

 https://github.com/zcgonvh/CVE-2020-0688

CVE-2021-1675

Windows Print Spooler权限提升漏洞

 https://nvd.nist.gov/vuln/detail/CVE-2021-1675

EXP/POC:

 https://github.com/cube0x0/CVE-2021-1675

CVE-2021-26855/CVE-2021-27065

Exchange ProxyLogon远程代码执行漏洞

 https://nvd.nist.gov/vuln/detail/CVE-2021-26855 https://nvd.nist.gov/vuln/detail/CVE-2021-27065

EXP/POC:

 https://github.com/hausec/ProxyLogon

CVE-2020-17144

Microsoft Exchange 远程代码执行漏洞

 https://nvd.nist.gov/vuln/detail/CVE-2020-17144

EXP/POC:

 https://github.com/Airboi/CVE-2020-17144-EXP

CVE-2020-16875

Microsoft Exchange 远程代码执行漏洞

 https://nvd.nist.gov/vuln/detail/CVE-2020-16875

EXP/POC:

 https://srcincite.io/pocs/cve-2020-16875.py.txt

CVE-2021-34473

Exchange ProxyShell SSRF

 https://nvd.nist.gov/vuln/detail/CVE-2021-34473

EXP/POC:

 https://github.com/dmaasland/proxyshell-poc

CVE-2021-33766

Exchange ProxyToken 信息泄露漏洞

 https://nvd.nist.gov/vuln/detail/CVE-2021-33766

EXP/POC:

 https://github.com/bhdresh/CVE-2021-33766-ProxyToken

文章排版:Top security

侵权请私聊公众号删文



文章来源: http://mp.weixin.qq.com/s?__biz=MzAxMjE3ODU3MQ==&mid=2650536630&idx=2&sn=dc72f6f9adcee1f84a98bf179df1ad17&chksm=83ba9f52b4cd16442aec2408996c500ebf12ab1437f8ee8216a58784e4389f00972f0deecde3#rd
如有侵权请联系:admin#unsafe.sh