Description
This module exploits a buffer underrun vulnerability in Microsoft's DNSAPI.dll as distributed with Windows Vista and later without KB2509553. By sending a specially crafted LLMNR query, containing a leading '.' character, an attacker can trigger stack exhaustion or potentially cause stack memory corruption.
Although this vulnerability may lead to code execution, it has not been proven to be possible at the time of this writing.
NOTE: In some circumstances, a '.' may be found before the top of the stack is reached. In these cases, this module may not be able to cause a crash.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use auxiliary/dos/windows/llmnr/ms11/030_dnsapimsf undefined(030_dnsapi) > show actions ...actions...msf undefined(030_dnsapi) > set ACTION < action-name >msf undefined(030_dnsapi) > show options ...show and set options...msf undefined(030_dnsapi) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub