zoukankan      html  css  js  c++  java
  • Windows系统CVE整理

    CVE-2019-1181

    Date
    2019.8
    
    类型
    
    影响范围

     

    CVE-2019-0708

    Date
    2019.5
    
    类型
    远程代码执行
    
    影响范围
    
    复现
    POC
    0708detector.exe -t 192.168.91.138(要测试的目标IP) -p 3389
    EXP EXP目前仅支持 WIN7 SP1 和 Windows Server 2008 R2
    分析

    问题记录
    (1)已开启远程保护
    我的电脑”→“属性”→“远程设置”→“远程”,启用网路级认证(NLA)
     (2)
     

     

    CVE-2018-8420(RCE)

    受影响版本:

     1 Microsoft Windows 10 Version 1607 for 32-bit Systems
     2 Microsoft Windows 10 Version 1607 for x64-based Systems
     3 Microsoft Windows 10 Version 1803 for 32-bit Systems
     4 Microsoft Windows 10 Version 1803 for x64-based Systems
     5 Microsoft Windows 10 for 32-bit Systems
     6 Microsoft Windows 10 for x64-based Systems
     7 Microsoft Windows 10 version 1703 for 32-bit Systems
     8 Microsoft Windows 10 version 1703 for x64-based Systems
     9 Microsoft Windows 10 version 1709 for 32-bit Systems
    10 Microsoft Windows 10 version 1709 for x64-based Systems
    11 Microsoft Windows 7 for 32-bit Systems SP1
    12 Microsoft Windows 7 for x64-based Systems SP1
    13 Microsoft Windows 8.1 for 32-bit Systems
    14 Microsoft Windows 8.1 for 64-bit Systems
    15 Microsoft Windows RT 8.1
    16 Microsoft Windows Server 1709
    17 Microsoft Windows Server 1803
    18 Microsoft Windows Server 2008 R2 for Itanium-based Systems SP1
    19 Microsoft Windows Server 2008 R2 for x64-based Systems SP1
    20 Microsoft Windows Server 2008 for 32-bit Systems SP2
    21 Microsoft Windows Server 2008 for Itanium-based Systems SP2
    22 Microsoft Windows Server 2008 for x64-based Systems SP2
    23 Microsoft Windows Server 2012
    24 Microsoft Windows Server 2012 R2
    25 Microsoft Windows Server 2016
    View Code

     win10和windows server 2016(2018-08-27 漏洞详情公开披露,2018-08-29 360CERT发布漏洞预警)

    1 Task Scheduler任务调度服务中ALPC调用接口导出了SchRpcSetSecurity函数,该函数能够对一个任务或者文件夹设置安全描述符
    View Code

    Windows VBScript Engine (RCE) CVE-2018-8174 

    1 https://github.com/Sch01ar/CVE-2018-8174_EXP
    View Code
  • 相关阅读:
    MVP模式与MVVM模式
    webpack的配置处理
    leetcode 287 Find the Duplicate Number
    leetcode 152 Maximum Product Subarray
    leetcode 76 Minimum Window Substring
    感知器算法初探
    leetcode 179 Largest Number
    leetcode 33 Search in Rotated Sorted Array
    leetcode 334 Increasing Triplet Subsequence
    朴素贝叶斯分类器初探
  • 原文地址:https://www.cnblogs.com/AtesetEnginner/p/11194963.html
Copyright © 2011-2022 走看看