Warning
This project was created strictly for educational, research, and authorized security testing purposes!
The authors take no responsibility for your actions or any damage caused by this software!
Q. What is this? Proof of Concept (PoC) for a Zero-Click Remote Code Execution (RCE) vulnerability on the XWorm server.
Q. How does the vulnerability work? XWorm contains an input sanitization vulnerability in its RDP connection plugin:
- The client sends connection data to the server.
- The server constructs a command line and launches
mstsc.exe(the built-in Windows RDP client) with the provided arguments.
- The server does not validate or sanitize the client's response;
- An attacker doesn't even need the server operator to manually issue a request to the plugin.
- Download the binary from the Releases section (or compile it from source).
- Enter the required details for the target server.
- Enter the command you want to execute on the server side.
- Send the payload.
Note
For safety reasons, research this strictly inside an isolated virtual machine (VM).
#FuckXWorm
