CVE-2023-34758High· 8.1▾ TwilightSilver vulnerable to MitM attack against implants due to a cryptography vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
The current cryptography implementation in Sliver up to version 1.5.39 allows a MitM with access to the corresponding implant binary to execute arbitrary codes on implanted devices via intercepted and crafted responses. (Reserved CVE ID: CVE-2023-34758)
Please see the PoC repo.
Please also see the PoC repo. To setup a simple PoC environment,
notepad.exe window should pop up on the implanted VM.A successful attack grants the attacker permission to execute arbitrary code on the implanted device.
https://github.com/BishopFox/sliver/blob/master/implant/sliver/cryptography/implant.go
https://github.com/BishopFox/sliver/blob/master/implant/sliver/cryptography/crypto.go
https://github.com/tangent65536/Slivjacker
Ting-Wei Hsieh from CHT Security Co. Ltd.
github.com/bishopfox/sliver >= 1.5.0, < 1.5.40Upgrade to a patched release:
github.com/bishopfox/sliver 1.5.40Connected by shared product, vendor, weakness, or advisory.