• Stars
    star
    294
  • Rank 141,303 (Top 3 %)
  • Language
    C++
  • Created almost 2 years ago
  • Updated almost 2 years ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

CVE-2023-21752

PoC for arbitrary file delete vulnerability in Windows Backup service.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21752

This repo contains two exploits:

v1 - Just perform file delete of user choice

v2 - Tries to abuse arb delete to spawn elevated cmd shell (not very stable probably need to run it couple of times, better work on phisycal machine)

poc.mp4

Timeline

  • 07/07/2022 - Vulnerability reported to MSRC
  • 08/10/2022 - MSRC confirmed vulnerability
  • 08/12/2022 - Bounty awarded
  • 01/10/2023 - Patch released