@msftsecresponse said that CVE-2021-1675 is just LPE, so maybe this 100% stable RCE as SYSTEM on Domain Controller is another one?
pic.twitter.com/x58lbnnqso
-
-
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-1675 … does state LPE only, would also be interested to learn more details - the PoC demo shows some network interaction, but under what user? is it authenticated? The payload shown is also running in a local context on the DC. Would love to know more details!
-
I think any user can exploit this vulnerability, no special privilege is required. In the demo, we use NTLM relay to acquire a Normal Domain User, that's why it exploits two times. It is authenticated or not depends on your opinion on NTLM relay. ^_^
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.