Exploits / Vulnerability Discovered : 2020-01-10 |
Type : local |
Platform : windows
This exploit / vulnerability Totalav 2020 4.14.31 privilege escalation is for educational purposes only and if it is used you will do on your own risk!
# Vulnerability Description:
# TotalAV 2020 4.14.31 has quarantine flaw that allows attacker escape of
# privilege by using NTFS directory junction.
**You can download vulnerability version with this link:
https://install.protected.net/windows/cdn3/4.14.31/TotalAV_Setup.exe
///////////////////////////////////
Proof of Concept
//////////////////////////////////
1. Plant the malicious file in this case we use DLL file
2. To exploit the vulnerability antivirus must detect the malicious dll
3. Move it to quarantine.
4. Attacker must create NTFS directory junction to restore
Full step: https://www.youtube.com/watch?v=88qeaLq98Gc