[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fwbZrQxvh5SQEOhfn_LvKJYXUIdmaoe_55AKycImXJUY":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},102,"How can users defend against the CVE-2017-8464 LNK vulnerability?","Users should install the official Microsoft patch for CVE-2017-8464, available from the Microsoft Security Response Center. As an additional measure, disabling the USB AutoPlay feature prevents automatic triggering of malicious .lnk files from removable drives. For a full list of recommended defenses and links to the patch and third‑party tools, refer to the [Exploitation Testing of Windows Lnk Remote Code Execution Vulnerability (CVE-2017-8464)](\u002Fnews\u002Fexploitation-testing-of-windows-lnk-remote-code-execution-vulnerability-cve-2017-8464) article.","\u003Cp>Users should install the official Microsoft patch for CVE-2017-8464, available from the Microsoft Security Response Center. As an additional measure, disabling the USB AutoPlay feature prevents automatic triggering of malicious .lnk files from removable drives. For a full list of recommended defenses and links to the patch and third‑party tools, refer to the [Exploitation Testing of Windows Lnk Remote Code Execution Vulnerability (CVE-2017-8464)](\u002Fnews\u002Fexploitation-testing-of-windows-lnk-remote-code-execution-vulnerability-cve-2017-8464) article.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fexploitation-testing-of-windows-lnk-remote-code-execution-vulnerability-cve-2017-8464\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-users-defend-against-the-cve-2017-8464-lnk-vulnerability-1777485199608","patch, USB AutoPlay, defense, CVE-2017-8464, Microsoft security",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},26,"Exploitation Testing of Windows Lnk Remote Code Execution Vulnerability (CVE-2017-8464)","exploitation-testing-of-windows-lnk-remote-code-execution-vulnerability-cve-2017-8464","Test and exploit CVE-2017-8464 Windows LNK RCE vulnerability. Learn to fix Metasploit script bugs for perfect exploitation without crashing explorer.exe.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the early morning of June 14th Beijing time, Microsoft released a vulnerability bulletin numbered CVE-2017-8464. The official announcement states that the Windows system contains a high-risk vulnerability allowing remote execution of arbitrary code when parsing shortcuts. Attackers can trigger this vulnerability through USB drives, network shares, and other means to gain complete control over the user's system, posing a high security risk.\u003C\u002Fp>\u003Cp>The principle of this vulnerability is very similar to the Stuxnet virus used in the 2010 Stuxnet operation, allegedly by the United States and Israel to infiltrate and sabotage Iran's nuclear facilities, leading some to call it \"Stuxnet 3.0.\"\u003C\u002Fp>\u003Cp>However, some domestic articles found by searching the keyword \"cve-2017-8464复现\" on Baidu have misunderstood the reproduction of this vulnerability, mistakenly treating the execution of PowerShell code via shortcuts as the exploitation method.\u003C\u002Fp>\u003Cp>Therefore, this article aims to correct this mistake.\u003C\u002Fp>\u003Cp>Additionally, there is a bug in the currently available Metasploit exploit script for testing, where the process explorer.exe crashes after the vulnerability is triggered, making the exploitation imperfect.\u003C\u002Fp>\u003Cp>Considering that more than 45 days have passed since the patch was publicly released, this article will disclose the method to fix the bug in the exploit script, achieving \"perfect exploitation\" of this vulnerability.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Vulnerability Overview\u003C\u002Fli>\u003Cli>Vulnerability Testing\u003C\u002Fli>\u003Cli>Bug Fix\u003C\u002Fli>\u003Cli>Defense\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Vulnerability Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This vulnerability is a remote code execution flaw that occurs during the processing of LNK files in Microsoft Windows systems.\u003C\u002Fp>\u003Cp>When a vulnerable computer is connected to a USB drive containing malicious software, the exploit can take complete control of the user's system without any additional action.\u003C\u002Fp>\u003Cp>The vulnerability can also be triggered and exploited through user activities such as accessing network shares, downloading files from the internet, or copying files.\u003C\u002Fp>\u003Cp>In other words, the vulnerability can be triggered under any of the following conditions:\u003C\u002Fp>\u003Cp>1. The system has auto-play enabled for USB drives, and a USB drive is inserted, triggering the vulnerability.\u003C\u002Fp>\u003Cp>2. Accessing the file directory via network sharing.\u003C\u002Fp>\u003Cp>3. Directly accessing the file directory.\u003C\u002Fp>\u003Ch2>0x03 Vulnerability Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Currently, there are two publicly available scripts for testing and exploitation:\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Metasploit exploit script\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Author: ykoster\u003C\u002Fp>\u003Cp>Download link: https:\u002F\u002Fgithub.com\u002Frapid7\u002Fmetasploit-framework\u002Fpull\u002F8767\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Python exploitation script\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Author: nixawk\u003C\u002Fp>\u003Cp>Download link: https:\u002F\u002Fgithub.com\u002Fnixawk\u002Flabs\u002Fblob\u002Fmaster\u002FCVE-2017-8464\u002Fexploit_CVE-2017-8464.py\u003C\u002Fp>\u003Cp>This article focuses on testing the msf script, copying the exp to a USB drive, and testing the exploitation method triggered via USB drive\u003C\u002Fp>\u003Ch3>Actual testing:\u003C\u002Fh3>\u003Cp>Test system: Kali 2.0\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Download msf script\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cd \u002Fusr\u002Fshare\u002Fmetasploit-framework\u002Fmodules\u002Fexploits\u002Fwindows\u002Ffileformat\u002F\u003Cbr>wget https:\u002F\u002Fraw.githubusercontent.com\u002Fykoster\u002Fmetasploit-framework\u002F169e00bf3442447324df064192db62cdc5b5b860\u002Fmodules\u002Fexploits\u002Fwindows\u002Ffileformat\u002Fcve_2017_8464_lnk_rce.rb\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>2. Generate exp\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>use exploits\u002Fwindows\u002Ffileformat\u002Fcve_2017_8464_lnk_rce\u003Cbr>set payload windows\u002Fx64\u002Fexec\u003Cbr>set cmd calc.exe\u003Cbr>set EXITFUNC thread\u003Cbr>exploit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The default msf script corresponds to the Windows x64 system, so the payload should also be 64-bit exec\u003C\u002Fp>\u003Cp>Parameter settings are as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019810706_0_85ce1ab9f6.jpeg\">\u003C\u002Fp>\u003Cp>After execution, 24 exploit files are generated in \u002Froot\u002F.msf4\u002Flocal\u002F, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019822571_1_9a9773e983.jpeg\">\u003C\u002Fp>\u003Cp>In kali2.0, this folder cannot be accessed directly; you can copy all files from \u002Froot\u002F.msf4\u002Flocal\u002F to \u002Froot\u002F1 via command line\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Cp>cp -r \u002Froot\u002F.msf4\u002Flocal\u002F \u002Froot\u002F1\u003C\u002Fp>\u003Cp>Copy the files, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019833407_2_02805a52da.jpeg\">\u003C\u002Fp>\u003Cp>Copy the above files to a USB drive and test on another unpatched Win7 x64 system\u003C\u002Fp>\u003Cp>\u003Cstrong>3、Testing\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Successfully executed calc.exe, but the explorer.exe process crashed\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019854232_3_ef54b08ead.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The exploit script in the USB drive can be deleted by formatting the USB drive\u003C\u002Fp>\u003Cp>Then the following tests were conducted respectively:\u003C\u002Fp>\u003Cul>\u003Cli>Test Win10 x64\u003C\u002Fli>\u003Cli>Change payload: set payload windows\u002Fx64\u002Fmeterpreter\u002Freverse_tcp\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Still the same result\u003C\u002Fp>\u003Cp>Check GitHub, others have encountered the same issue, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019864599_4_e9762ca164.jpeg\">\u003C\u002Fp>\u003Cp>More replies at: https:\u002F\u002Fgithub.com\u002Frapid7\u002Fmetasploit-framework\u002Fpull\u002F8767\u003C\u002Fp>\u003Cp>\u003Cstrong>4. More tests\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Attempt to test 32-bit systems\u003C\u002Fp>\u003Cp>This script supports 32-bit systems, switch command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>set target 1\u003Cbr>set payload windows\u002Fexec\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019868180_5_8800fa88dd.jpeg\">\u003C\u002Fp>\u003Cp>however, the test results were unsatisfactory and still failed\u003C\u002Fp>\u003Ch2>0x04 bug fix\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>omitting the debugging process, directly providing the simplest solution:\u003Cstrong>replace the dll\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>the msf exploit script generated a total of 24 files, consisting of 1 dll file and 23 lnk files\u003C\u002Fp>\u003Cp>as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019872303_6_8d54d2cec5.jpeg\">\u003C\u002Fp>\u003Cp>Note:\u003C\u002Fp>\u003Cp>for the 23 lnk files, the last character of the filename represents the USB drive letter. If the test system's USB drive is E:, then only keep the lnk file whose last character is \"E\", and the other lnk files can be deleted\u003C\u002Fp>\u003Cp>the cause of the bug lies in the dll, simply replace it with your own dll\u003C\u002Fp>\u003Cp>32-bit dll download address for testing:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>64-bit testable DLL download link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Does not cause explorer.exe process crash, test as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019876532_7_8b63355ac6.jpeg\">\u003C\u002Fp>\u003Cp>Test of triggering vulnerability via USB auto-play as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019881215_8_d90c09766a.png\">\u003C\u002Fp>\u003Cp>Bug successfully fixed at this point\u003C\u002Fp>\u003Cp>Test EXP link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Install patches\u003C\u002Fh3>\u003Cp>Microsoft official patch download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fportal.msrc.microsoft.com\u002Fen-us\u002Fsecurity-guidance\u002Fadvisory\u002FCVE-2017-8464\u003C\u002Fp>\u003Cp>360 Vulnerability Patch Repair Tool download address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fb.360.cn\u002Fother\u002Fstuxnet3fixtool\u003C\u002Fp>\u003Ch3>2. Disable USB AutoPlay function\u003C\u002Fh3>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tests the msf exploit script for CVE-2017-8464, fixes bugs within it, and achieves 'perfect exploitation' of this vulnerability at the technical level. Do not use for illegal purposes. We hereby remind ordinary users again of the necessity to apply patches regularly.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the early morning of June 14th Beijing time, Microsoft released a vulnerability bulletin numbered CVE-2017-8464. The official announcement states that the Windows system contains a high-risk vulnerability allowing remote execution of arbitrary code when parsing shortcuts. Attackers can trigger this vulnerability through USB drives, network shares, and other means to gain complete control over the user's system, posing a high security risk.\u003C\u002Fp>\u003Cp>The principle of this vulnerability is very similar to the Stuxnet virus used in the 2010 Stuxnet operation, allegedly by the United States and Israel to infiltrate and sabotage Iran's nuclear facilities, leading some to call it \"Stuxnet 3.0.\"\u003C\u002Fp>\u003Cp>However, some domestic articles found by searching the keyword \"cve-2017-8464复现\" on Baidu have misunderstood the reproduction of this vulnerability, mistakenly treating the execution of PowerShell code via shortcuts as the exploitation method.\u003C\u002Fp>\u003Cp>Therefore, this article aims to correct this mistake.\u003C\u002Fp>\u003Cp>Additionally, there is a bug in the currently available Metasploit exploit script for testing, where the process explorer.exe crashes after the vulnerability is triggered, making the exploitation imperfect.\u003C\u002Fp>\u003Cp>Considering that more than 45 days have passed since the patch was publicly released, this article will disclose the method to fix the bug in the exploit script, achieving \"perfect exploitation\" of this vulnerability.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Vulnerability Overview\u003C\u002Fli>\u003Cli>Vulnerability Testing\u003C\u002Fli>\u003Cli>Bug Fix\u003C\u002Fli>\u003Cli>Defense\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Vulnerability Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This vulnerability is a remote code execution flaw that occurs during the processing of LNK files in Microsoft Windows systems.\u003C\u002Fp>\u003Cp>When a vulnerable computer is connected to a USB drive containing malicious software, the exploit can take complete control of the user's system without any additional action.\u003C\u002Fp>\u003Cp>The vulnerability can also be triggered and exploited through user activities such as accessing network shares, downloading files from the internet, or copying files.\u003C\u002Fp>\u003Cp>In other words, the vulnerability can be triggered under any of the following conditions:\u003C\u002Fp>\u003Cp>1. The system has auto-play enabled for USB drives, and a USB drive is inserted, triggering the vulnerability.\u003C\u002Fp>\u003Cp>2. Accessing the file directory via network sharing.\u003C\u002Fp>\u003Cp>3. Directly accessing the file directory.\u003C\u002Fp>\u003Ch2>0x03 Vulnerability Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Currently, there are two publicly available scripts for testing and exploitation:\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Metasploit exploit script\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Author: ykoster\u003C\u002Fp>\u003Cp>Download link: https:\u002F\u002Fgithub.com\u002Frapid7\u002Fmetasploit-framework\u002Fpull\u002F8767\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Python exploitation script\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Author: nixawk\u003C\u002Fp>\u003Cp>Download link: https:\u002F\u002Fgithub.com\u002Fnixawk\u002Flabs\u002Fblob\u002Fmaster\u002FCVE-2017-8464\u002Fexploit_CVE-2017-8464.py\u003C\u002Fp>\u003Cp>This article focuses on testing the msf script, copying the exp to a USB drive, and testing the exploitation method triggered via USB drive\u003C\u002Fp>\u003Ch3>Actual testing:\u003C\u002Fh3>\u003Cp>Test system: Kali 2.0\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Download msf script\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cd \u002Fusr\u002Fshare\u002Fmetasploit-framework\u002Fmodules\u002Fexploits\u002Fwindows\u002Ffileformat\u002F\u003Cbr>wget https:\u002F\u002Fraw.githubusercontent.com\u002Fykoster\u002Fmetasploit-framework\u002F169e00bf3442447324df064192db62cdc5b5b860\u002Fmodules\u002Fexploits\u002Fwindows\u002Ffileformat\u002Fcve_2017_8464_lnk_rce.rb\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>2. Generate exp\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>use exploits\u002Fwindows\u002Ffileformat\u002Fcve_2017_8464_lnk_rce\u003Cbr>set payload windows\u002Fx64\u002Fexec\u003Cbr>set cmd calc.exe\u003Cbr>set EXITFUNC thread\u003Cbr>exploit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The default msf script corresponds to the Windows x64 system, so the payload should also be 64-bit exec\u003C\u002Fp>\u003Cp>Parameter settings are as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019810706_0_85ce1ab9f6-1.jpeg\">\u003C\u002Fp>\u003Cp>After execution, 24 exploit files are generated in \u002Froot\u002F.msf4\u002Flocal\u002F, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019822571_1_9a9773e983-1.jpeg\">\u003C\u002Fp>\u003Cp>In kali2.0, this folder cannot be accessed directly; you can copy all files from \u002Froot\u002F.msf4\u002Flocal\u002F to \u002Froot\u002F1 via command line\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Cp>cp -r \u002Froot\u002F.msf4\u002Flocal\u002F \u002Froot\u002F1\u003C\u002Fp>\u003Cp>Copy the files, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019833407_2_02805a52da-1.jpeg\">\u003C\u002Fp>\u003Cp>Copy the above files to a USB drive and test on another unpatched Win7 x64 system\u003C\u002Fp>\u003Cp>\u003Cstrong>3、Testing\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Successfully executed calc.exe, but the explorer.exe process crashed\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019854232_3_ef54b08ead-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The exploit script in the USB drive can be deleted by formatting the USB drive\u003C\u002Fp>\u003Cp>Then the following tests were conducted respectively:\u003C\u002Fp>\u003Cul>\u003Cli>Test Win10 x64\u003C\u002Fli>\u003Cli>Change payload: set payload windows\u002Fx64\u002Fmeterpreter\u002Freverse_tcp\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Still the same result\u003C\u002Fp>\u003Cp>Check GitHub, others have encountered the same issue, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019864599_4_e9762ca164-1.jpeg\">\u003C\u002Fp>\u003Cp>More replies at: https:\u002F\u002Fgithub.com\u002Frapid7\u002Fmetasploit-framework\u002Fpull\u002F8767\u003C\u002Fp>\u003Cp>\u003Cstrong>4. More tests\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Attempt to test 32-bit systems\u003C\u002Fp>\u003Cp>This script supports 32-bit systems, switch command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>set target 1\u003Cbr>set payload windows\u002Fexec\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019868180_5_8800fa88dd-1.jpeg\">\u003C\u002Fp>\u003Cp>however, the test results were unsatisfactory and still failed\u003C\u002Fp>\u003Ch2>0x04 bug fix\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>omitting the debugging process, directly providing the simplest solution:\u003Cstrong>replace the dll\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>the msf exploit script generated a total of 24 files, consisting of 1 dll file and 23 lnk files\u003C\u002Fp>\u003Cp>as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019872303_6_8d54d2cec5-1.jpeg\">\u003C\u002Fp>\u003Cp>Note:\u003C\u002Fp>\u003Cp>for the 23 lnk files, the last character of the filename represents the USB drive letter. If the test system's USB drive is E:, then only keep the lnk file whose last character is \"E\", and the other lnk files can be deleted\u003C\u002Fp>\u003Cp>the cause of the bug lies in the dll, simply replace it with your own dll\u003C\u002Fp>\u003Cp>32-bit dll download address for testing:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>64-bit testable DLL download link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Does not cause explorer.exe process crash, test as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019876532_7_8b63355ac6-1.jpeg\">\u003C\u002Fp>\u003Cp>Test of triggering vulnerability via USB auto-play as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019881215_8_d90c09766a-1.png\">\u003C\u002Fp>\u003Cp>Bug successfully fixed at this point\u003C\u002Fp>\u003Cp>Test EXP link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Install patches\u003C\u002Fh3>\u003Cp>Microsoft official patch download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fportal.msrc.microsoft.com\u002Fen-us\u002Fsecurity-guidance\u002Fadvisory\u002FCVE-2017-8464\u003C\u002Fp>\u003Cp>360 Vulnerability Patch Repair Tool download address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fb.360.cn\u002Fother\u002Fstuxnet3fixtool\u003C\u002Fp>\u003Ch3>2. Disable USB AutoPlay function\u003C\u002Fh3>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tests the msf exploit script for CVE-2017-8464, fixes bugs within it, and achieves 'perfect exploitation' of this vulnerability at the technical level. Do not use for illegal purposes. We hereby remind ordinary users again of the necessity to apply patches regularly.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1711,"Onedaysec",4,"published","2026-02-02T08:20:05.022Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Exploit CVE-2017-8464 Windows LNK RCE Vulnerability Testing & Bug Fix","CVE-2017-8464, Windows LNK vulnerability, remote code execution, Stuxnet 3.0, Metasploit exploit, bug fix, security testing, USB drive attack",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],103,101,100,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.441Z","2026-07-23T16:01:00.868Z","draft","2026-07-23T16:03:37.038Z"]