Diagnostic tracking service will in SYSTEM security context copy xml files from C:\Users\user\AppData\Local\Packages\http://Microsoft.Windows .ContentDeliveryManager_cw5n1h2txyewy\LocalState\Tips\ to C:\ProgramData\Microsoft\Diagnosis\SoftLandingStage\
-
-
Show this thread
-
back then I redirected the copy source folder to the namedpipe device. Because the named pipe file system allows directory listings it will try and copy a named pipe with .xml extension But named pipes can have ..\ in the name
Show this thread -
So when that is used as filename in the copy operation we escape the intended dirs and end up copy my payload into system32.
Show this thread -
Along comes the projected file system- again allowing us to specify invalid filenames in directory listings.https://twitter.com/jonasLyk/status/1265551125593362432 …
Show this thread -
So, rince and repeat- There is probaly more ways to do this. Like webdav? You can probaly fake such file names easily with that
Show this thread
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

See: