vendor:
Windows
by:
Exploit Database
7.8
CVSS
HIGH
Composite Moniker
119
CWE
Product Name: Windows
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2017-8570
CPE: None
Other Scripts:
N/A
Platforms Tested: Windows
2017
Composite Moniker Vulnerability Exploit
This repo contains a Proof of Concept exploit for CVE-2017-8570, a.k.a the 'Composite Moniker' vulnerability. This demonstrates using the Packager.dll trick to drop an sct file into the %TEMP% directory, and then execute it using the primitive that the vulnerability provides.
Mitigation:
Microsoft released a patch for this vulnerability in July 2017. Users should ensure that they have the latest security updates installed.