Original source:
https://malvuln.com/advisory/34fb086a88f3a2506b61a17cced3b476.txt
Contact:
Media: twitter.com/malvuln
Threat: Trojan.Win32.Phires.zm
Vulnerability: Insecure Permissions
Description: The malware creates an dir with insecure
permissions
containing a registry file with a ".desc" extension, under c:\
drive
granting change (C) permissions to the authenticated user group.
Standard
users can rename the file dropped by the malware to disable it or
replace
it with their own. Then wait for a privileged user to logon to the
infected
machine to potentially escalate privileges.
Type: PE32
MD5: 34fb086a88f3a2506b61a17cced3b476
Vuln ID: MVID-2021-0384
Dropped files: info.desc
Disclosure: 11/01/2021
Exploit/PoC:
C:\> cacls Adobes
C:\Adobes BUILTIN\Administrators:(OI)(CI)(ID)F
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Users:(OI)(CI)(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C
C:\>dir Adobes
Volume in drive C has no label.
Directory of C:\Adobes
09/28/2010 03:29 PM 280 info.desc
1 File(s) 280 bytes
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.hae123.com"
Disclaimer: The information contained within this advisory is
supplied
"as-is" with no warranties or guarantees of fitness of use or
otherwise.
Permission is hereby granted for the redistribution of this
advisory,
provided that it is not altered except by reformatting it, and that
due
credit is given. Permission is explicitly given for insertion
in
vulnerability databases and similar, provided that due credit is
given to
the author. The author is not responsible for any misuse of the
information
contained herein and accepts no responsibility for any damage
caused by the
use or misuse of this information. The author prohibits any
malicious use
of security related information or exploits by the author or
elsewhere. Do
not attempt to download Malware samples. The author of this website
takes
no responsibility for any kind of damages occurring from improper
Malware
handling or the downloading of ANY Malware mentioned on this
website or
elsewhere. All content Copyright (c) Malvuln.com (TM).

