Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | MiniWeb HTTP Server ÎļþÉÏ´«Îó²î |
CVE ID | CVE-2013-10047 |
Îó²îÀàÐÍ | δÊÚȨÎļþÉÏ´« | ·¢Ã÷ʱ¼ä | 2025-08-04 |
Îó²îÆÀ·Ö | 9.3 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
MiniWeb HTTP Server ÊÇÒ»¿îÇáÁ¿¼¶µÄ¿ªÔ´ Web ЧÀÍÆ÷£¬£¬£¬£¬Ö¼ÔÚÌṩ¸ßЧ¡¢¾«Á·µÄ HTTP ЧÀÍ¡£¡£¡£¡£ËüÖ§³Ö»ù±¾µÄ Web ÇëÇó´¦Öóͷ££¬£¬£¬£¬ÊÊÓÃÓÚǶÈëʽװ±¸ºÍ×ÊÔ´ÊÜÏÞµÄÇéÐΡ£¡£¡£¡£MiniWeb ¾ßÓнÏСµÄÄÚ´æÕ¼ÓúͿìËÙµÄÏìÓ¦ËÙÂÊ£¬£¬£¬£¬ÊÊÊÊÓÃ×÷СÐÍÍøÕ¾»ò IoT ×°±¸µÄ Web ЧÀÍ¡£¡£¡£¡£
2025Äê8ÔÂ4ÈÕ£¬£¬£¬£¬918²©ÌìÌü¯ÍÅVSRC¼à²âµ½MiniWeb HTTP Server ¡Ü Build 300ÖеÄÒ»ÏîÑÏÖØÎó²î£¬£¬£¬£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÉÏ´«í§ÒâÎļþ¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý·¾¶±éÀúÎó²îÉÏ´«¶ñÒâ.exeÎļþÖÁϵͳĿ¼£¨ÈçSystem32£©£¬£¬£¬£¬²¢½øÒ»²½ÉÏ´«.mofÎļþÖÁWMIĿ¼£¬£¬£¬£¬Ê¹ÓÃWindowsÖÎÀí¹¤¾ßЧÀÍÒÔSYSTEMȨÏÞÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¸ÃÎó²î½öÓ°ÏìWindows Vista֮ǰµÄ°æ±¾¡£¡£¡£¡£Îó²îÆÀ·Ö9.3·Ö£¬£¬£¬£¬Îó²î¼¶±ðÑÏÖØ¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
Miniweb Http Server <= Build 300£¬£¬£¬£¬½öÓ°ÏìWindows Vista֮ǰµÄ°æ±¾¡£¡£¡£¡£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÞÖÆÉÏ´«ÎļþÀàÐÍ£ºÕ¥È¡ÉÏ´«.exe, .mofµÈ¿ÉÖ´ÐÐÎļþºÍ¾ç±¾Îļþ£¬£¬£¬£¬Ö»ÔÊÐíÉÏ´«·ÇÖ´ÐÐÎļþ£¨Èç.jpg, .pngµÈ£©¡£¡£¡£¡£Â·¾¶±éÀú·À»¤£º¶ÔÉÏ´«µÄÎļþ·¾¶¾ÙÐÐÑÏ¿áУÑ飬£¬£¬£¬È·±£ÎļþÎÞ·¨Í¨¹ý·¾¶±éÀú£¨Èç../£©ÉÏ´«µ½ÏµÍ³Ãô¸ÐĿ¼¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔʹÓÃÀο¿Ä¿Â¼ÏÞÖÆ»ò·¾¶¹æ·¶»¯»úÖÆ¡£¡£¡£¡£ÔöÇ¿Îļþ´æ´¢ÖÎÀí£º½«ÉÏ´«Îļþ´æ´¢ÔÚ¸ôÀëĿ¼ÖУ¬£¬£¬£¬²¢È·±£¸ÃĿ¼²»¿ÉÖ´ÐУ¬£¬£¬£¬×èÖ¹Îļþ±»ÎóÖ´ÐС£¡£¡£¡£ÌØÊâÊÇÔÚsystem32ºÍwbemµÈϵͳĿ¼ÖУ¬£¬£¬£¬Õ¥È¡ÎļþдÈë¡£¡£¡£¡£ÈÕÖ¾¼Í¼ÓëÉ󼯣ºÔöÇ¿ÎļþÉÏ´«²Ù×÷µÄÈÕÖ¾¼Í¼£¬£¬£¬£¬²¢°´ÆÚÉó¼ÆÉÏ´«¼Í¼£¬£¬£¬£¬ÊµÊ±·¢Ã÷²¢ÏìӦDZÔڵĶñÒâÎļþÉÏ´«ÐÐΪ¡£¡£¡£¡£
3.2 ÔÝʱ²½·¥
3.3 ͨÓý¨Òé
?°´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£?ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£?ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£?ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£?ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/http/miniweb_upload_wbem.rbhttps://www.exploit-db.com/exploits/27607