module

Microsoft SharePoint Server-Side Include and ViewState RCE

Disclosed
Oct 13, 2020
Created
Oct 19, 2020

Description

This module exploits a server-side include (SSI) in SharePoint to leak
the web.config file and forge a malicious ViewState with the extracted
validation key.

This exploit is authenticated and requires a user with page creation
privileges, which is a standard permission in SharePoint.

The web.config file will be stored in loot once retrieved, and the
VALIDATION_KEY option can be set to short-circuit the SSI and trigger
the ViewState deserialization.

Tested against SharePoint 2019 on Windows Server 2016.

Authors

Platform

Windows

Architectures

cmd, x86, x64

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use exploit/windows/http/sharepoint_ssi_viewstate
msf exploit(sharepoint_ssi_viewstate) > show targets
...targets...
msf exploit(sharepoint_ssi_viewstate) > set TARGET < target-id >
msf exploit(sharepoint_ssi_viewstate) > show options
...show and set options...
msf exploit(sharepoint_ssi_viewstate) > exploit

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.