Listen to this Post
This vulnerability exists within the Windows Server Update Service (WSUS) where the software insecurely deserializes user-supplied data without proper validation. Deserialization is the process of converting serialized data from a file or network stream back into an object. An attacker can exploit this by sending a specially crafted malicious serialized object to the WSUS server. When the server deserializes this untrusted data, it triggers the execution of arbitrary code within the context of the WSUS application, potentially granting the attacker full control over the system. As the service typically runs with high privileges, successful exploitation can lead to complete compromise of the WSUS server, allowing an attacker to deploy malware, steal sensitive update information, or use the server as a pivot point into the internal network. The attack can be performed remotely without authentication, making it highly severe.
Platform: Windows Server
Version: WSUS
Vulnerability: Deserialization RCE
Severity: Critical
date: 2022-01-11
Prediction: 2022-02-08
What Undercode Say:
`ysoserial.exe -f BinaryFormatter -g TypeConfuseDelegate -c “cmd /c calc.exe” > payload.bin`
`curl -X POST –data-binary @payload.bin http://target-wsus/api/endpoint`
Code analysis of the vulnerable component would show a direct call to `BinaryFormatter.Deserialize()` with unsanitized network input.
How Exploit:
Craft malicious serialized object.
Send object to WSUS API.
Trigger deserialization for RCE.
Protection from this CVE
Install Microsoft patch.
Block unnecessary ports.
Use application firewalls.
Impact:
Remote Code Execution
Network Compromise
Update Infrastructure Attack
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: www.cve.org
Extra Source Hub:
Undercode

