Trojan-Spy.Win32.SpyEyes.awow Insecure Permissions

Trojan-Spy.Win32.SpyEyes.awow Insecure Permissions

Trojan-Spy.Win32.SpyEyes.awow malware suffers from an insecure permissions vulnerability.

Exploit/PoC:

1
2
3
4
5
6
C:\>cacls $Recycle$
C:\$Recycle$ BUILTIN\Administrators:(OI)(CI)(ID)F
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Users:(OI)(CI)(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C