[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FD] Security advisory: Pre-authentication RCE in Wyn Enterprise 9.1.00145.0 (Mescius (GrapeCity))



0day Rubbish Research Team is publicly disclosing a vulnerability in Wyn 
Enterprise 9.1.00145.0 (Mescius (GrapeCity)). The research is published and a 
proof-of-concept is available.

Pre-authentication RCE (CVSS 9.8, pre-authentication)

Wyn Enterprise 9.1.00145.0 exposes an unauthenticated root RCE chain of three 
vulnerabilities: JWT signature validation is skipped (parse-only ReadToken) 
with a hardcoded integration client secret, producing an unauthenticated 
10-year admin reference token; the import endpoint allows a zip-slip arbitrary 
file write (a malicious DLL can be dropped into the security-provider folder); 
and the security-provider loader scans DLLs and calls Activator.CreateInstance 
on the parameterless constructor, running as root. All three are reachable 
without credentials in the default configuration. Dynamically verified with 
root RCE.

Impact: Full host compromise as root (the dotnet container process); the 
attacker can read the host filesystem, execute arbitrary commands, and take 
full control of the Wyn server.

Advisory: https://0day-rubbish.com/blog/wyn-enterprise-unauth-rce

PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish

-- 
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/