Windows Defender AV allows Everyone to read the configured exclusions on the system 🤦
reg query "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions" /s
#RemotePotato0 new release!
Now you can also grab and steal the NTLMv2 hashes of every user logged on a machine from an unprivileged user!
✅ works fully local - no network interaction (except win 2019)
✅ ntlm related
✅ won't fix
Windows in 2k21
cc @decoder_it
We are releasing an alternative way for elevating to SYSTEM when you have SeTcbPrivilege
How?
Leveraging AcquireCredentialsHandle through an SSPI hook that allows authenticating as SYSTEM to SCM
Should be "lighter" than the classic S4U
cc @decoder_itgist.github.com/antonioCoco/19…
Finally! I have found the right conditions to hit the vulnerable function for CVE-2022-26809!
No panic, this is a custom RPC server i wrote, not a default Windows service
It seems it's required a specific RPC configuration and AFAIK it shouldn't be common, need to deepen more...
🔥 Brace yourself #LocalPotato is out 🥔
Our new NTLM reflection attack in local authentication allows for arbitrary file read/write & elevation of privilege.
Patched by Microsoft, but other protocols may still be vulnerable.
cc @decoder_it
Enjoy! 👇
The slides of my talk “The Rise of Potatoes: Privilege Escalations in Windows Services” for Black Hat Asia 2021 are out!
👇🏽
i.blackhat.com/asia-21/Thursd…