CVE-2018-1803
published 2018-12-13CVE-2018-1803: IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 could allow a remote attacker to hijack the clicking action of the…
PriorityP427medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.18%
64.1th percentile
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 149702.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_access_manager | 9.0.1.0 – 9.0.5.0 | — |
| ibm | security_access_manager_appliance | — | — |
| ibm | security_access_manager_appliance | — | — |
| ibm | security_access_manager_appliance | — | — |
| ibm | security_access_manager_appliance | — | — |
| ibm | security_access_manager_appliance | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Microsoft Windows 10 - Theme API 'ThemePack' File Parsing
exploitdb·2020-01-29·CVSS 8.1
CVE-2018-8413 [HIGH] Microsoft Windows 10 - Theme API 'ThemePack' File Parsing
Microsoft Windows 10 - Theme API 'ThemePack' File Parsing
---
# Exploit Title: Microsoft Windows 10 - Theme API 'ThemePack' File Parsing
# Google Dork: n/a
# Date: 2020-10-28
# Exploit Author: Eduardo Braun Prado
# Vendor Homepage: http://www.microsoft.com/
# Software Link: http://www.microsoft.com/
# Version: 10 v.1803 (17134.407)
# Tested on: Windows 7, 8.0, 8.1, 10, Server 2012, Server 2012 R2, Server 2016, Server 2019
# CVE : CVE-2018-8413
# Discovered by: Eduardo Braun Prado
[Details]
Microsoft 'themepack' files are classic '.theme' files compressed for
sharing over the internet. Theme files
allows users to customize visual aspects of their device, such as icons
for known features like 'My computer'
and 'trash bin' folders, the default screensaver (which by the way
allowed attacke
Exploit-DB
Microsoft Windows - DSSVC CheckFilePermission Arbitrary File Deletion
exploitdb·2019-01-09
CVE-2018-8584 Microsoft Windows - DSSVC CheckFilePermission Arbitrary File Deletion
Microsoft Windows - DSSVC CheckFilePermission Arbitrary File Deletion
---
Windows: DSSVC CheckFilePermission Arbitrary File Delete EoP
Platform: Windows 10 1803 and 1809.
Class: Elevation of Privilege
Security Boundary (per Windows Security Service Criteria): User boundary
NOTE: This is one of multiple issues I’m reporting in the same service. While I’ve tried to ensure all the bugs are effectively orthogonal from each other it’s possible that fixes for one thing might affect others. I’ve also not reported every possible problem with the service as at some point I had to stop. I’ve not determined if any of these issues could be abusable from a sandbox, most of the issues almost certainly can’t be due to the requirements for arbitrary file symlinks but it’s not impossible.
Summary:
The
Exploit-DB
Microsoft Windows - DfMarshal Unsafe Unmarshaling Privilege Escalation
exploitdb·2018-11-20
CVE-2018-8550 Microsoft Windows - DfMarshal Unsafe Unmarshaling Privilege Escalation
Microsoft Windows - DfMarshal Unsafe Unmarshaling Privilege Escalation
---
Windows: DfMarshal Unsafe Unmarshaling Elevation of Privilege (Master)
Platform: Windows 10 1803 (not tested earlier, although code looks similar on Win8+)
Class: Elevation of Privilege
Note, this is the master issue report for the DfMarshal unmarshaler. I’m reporting multiple, non-exhaustive, issues in this marshaler in case you decide that you want to try and “fix” it rather than blocking the marshaler outright.
Summary: The unmarshaler for Storage objects is complete unsafe and yet is marked as a system trusted marshaler. There are multiple ways of abusing this to unmarshaler to get privilege escalation.
Description:
Storage objects are used by different parts of the OS and Office as a structured container
Exploit-DB
Microsoft Windows - 'FSCTL_FIND_FILES_BY_SID' Information Disclosure
exploitdb·2018-10-16
CVE-2018-8411 Microsoft Windows - 'FSCTL_FIND_FILES_BY_SID' Information Disclosure
Microsoft Windows - 'FSCTL_FIND_FILES_BY_SID' Information Disclosure
---
Windows: FSCTL_FIND_FILES_BY_SID Information Disclosure
Platform: Windows 10 (1709, 1803)
Class: Information Disclosure / Elevation of Privilege
Summary: The FSCTL_FIND_FILES_BY_SID control code doesn’t check for permissions to list a directory leading to disclosure of file names when a user is not granted FILE_LIST_DIRECTORY access.
Description: The FSCTL_FIND_FILES_BY_SID is documented to return a list of files in a directory for a specific owner. This only works when Quotas are tracked on the device which isn’t a default configuration, but could be common especially on shared terminal servers. The FSCTL code is specified for FILE_ANY_ACCESS so it’s possible to issue it for any handle on a directory regardless o
Exploit-DB
RICOH MP C1803 JPN Printer - Cross-Site Scripting
exploitdb·2018-10-03·CVSS 6.1
CVE-2018-17310 [MEDIUM] RICOH MP C1803 JPN Printer - Cross-Site Scripting
RICOH MP C1803 JPN Printer - Cross-Site Scripting
---
# Exploit Title: RICOH MP C1803 JPN Printer - Cross-Site Scripting
# Date: 2018-09-21
# Exploit Author: Ismail Tasdelen
# Vendor Homepage: https://www.ricoh.com/
# Hardware Link : https://www.ricoh.co.jp/mfp/mp_c/1803/
# Software : RICOH Printer
# Product Version: MP C1803 JPN
# Vulernability Type : Code Injection
# Vulenrability : HTML Injection and Stored XSS
# Affected Products: RICOH MP C1803 JPN, RICOH MP C307
# CVE : CVE-2018-17310, CVE-2018-17313
# On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have
# been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
# HTTP POST Request :
POST /web/entry/en/address/adrsSetUserWizard.
Exploit-DB
Microsoft Windows - 'CiSetFileCache' WDAC Security Feature Bypass TOCTOU
exploitdb·2018-09-19·CVSS 5.3
CVE-2018-8449 [MEDIUM] Microsoft Windows - 'CiSetFileCache' WDAC Security Feature Bypass TOCTOU
Microsoft Windows - 'CiSetFileCache' WDAC Security Feature Bypass TOCTOU
---
Windows: CiSetFileCache TOCTOU CVE-2017-11830 Variant WDAC Security Feature Bypass
Platform: Windows 10 1803, 1709 (should include S-Mode but not tested)
Class: Security Feature Bypass
Summary:
While the TOCTOU attack against cache signing has been mitigated through NtSetCachedSigningLevel it’s possible to reach the same code via NtCreateSection leading to circumventing WDAC policies and CIG/PPL.
Description:
I'm reporting this as you've fixed the previous issues (cases 43036 and 40101) so I'm making an assumption you'd also fix this one. The previous issues allowed a unprivileged caller to exploit a race condition in the CiSetFileCache kernel function by calling NtSetCachedSigningLevel. These issues should no
Exploit-DB
Microsoft Windows - Double Dereference in NtEnumerateKey Elevation of Privilege
exploitdb·2018-09-19
CVE-2018-8410 Microsoft Windows - Double Dereference in NtEnumerateKey Elevation of Privilege
Microsoft Windows - Double Dereference in NtEnumerateKey Elevation of Privilege
---
Windows: Double Dereference in NtEnumerateKey Elevation of Privilege
Platform: Windows 10 1803 (not vulnerable in earlier versions)
Class: Elevation of Privilege
Summary: A number of registry system calls do not correctly handle pre-defined keys resulting in a double dereference which can lead to EoP.
Description:
The registry contains a couple of predefined keys, to generate performance information. These actually exist in the the machine hive under \Registry\Machine\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib. When these keys are opened the kernel returns a status code of STATUS_PREDEFINED_KEY, but it also returns a handle to the key.
The kernel doesn’t allow these keys to be used for many
Exploit-DB
STOPzilla AntiMalware 6.5.2.59 - Privilege Escalation (1)
exploitdb·2018-09-13
STOPzilla AntiMalware 6.5.2.59 - Privilege Escalation (1)
STOPzilla AntiMalware 6.5.2.59 - Privilege Escalation (1)
---
/*
# Exploit Title: STOPzilla AntiMalware 6.5.2.59 - Privilege Escalation
# Date: 2018-09-13
# Author: Parvez Anwar (@parvezghh)
# Vendor Homepage: https://www.stopzilla.com/
# Software link: https://download.stopzilla.com/binaries/stopzilla/auto_installer/STOPzillaAntiMalware.msi
# Tested Version: 6.5.2.59
# Driver Version: 3.0.23.0 - szkg64.sys
# Tested on OS: 64bit Windows 7 and Windows 10 (1803)
# CVE ID: N/A
# Vendor fix url - No response from vendor
# Fixed Version - 0day
# Fixed driver ver - 0day
# https://www.greyhathacker.net/?p=1025
*/
#include
#include
#include
#include
#pragma comment(lib,"winsta.lib")
#pragma comment(lib,"advapi32.lib")
#define SystemHandleInformation 16
#define STATUS_INFO_LENGTH_MISMATCH ((N
No writeups or analysis indexed.
2018-12-13
Published