Description
This module exploits a vulnerability in the MS10-046 patch to abuse (again) the handling of Windows Shortcut files (.LNK) that contain an icon resource pointing to a malicious DLL. This module creates the required files to exploit the vulnerability. They must be uploaded to an UNC path accessible by the target. This module has been tested successfully on Windows 2003 SP2 with MS10-046 installed and Windows 2008 SP2 (32 bits) with MS14-027 installed.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/windows/fileformat/ms15/020_shortcut_icon_dllloadermsf undefined(020_shortcut_icon_dllloader) > show actions ...actions...msf undefined(020_shortcut_icon_dllloader) > set ACTION < action-name >msf undefined(020_shortcut_icon_dllloader) > show options ...show and set options...msf undefined(020_shortcut_icon_dllloader) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub