ZeroHour
Lobsters · securitypublished ()ingested mannulinux.org via hoistbypetard

Privilege escalation from IIS AppPool to NT Authority/SYSTEM

mediumResearchimportance 42
AI summary · glm-5.3-flash

A write-up demonstrates privilege escalation from an IIS AppPool identity to NT AUTHORITY/SYSTEM via the AD CS RPC endpoint.

A technical write-up details a Windows privilege escalation path that moves an IIS application pool identity to NT AUTHORITY/SYSTEM by abusing the Active Directory Certificate Services RPC endpoint. The technique chains the restricted IIS AppPool service context with AD CS access to reach SYSTEM on the host. The post is relevant for defenders mapping privilege escalation paths on Windows web servers.

  • Starts from the restricted IIS AppPool service context
  • Abuses the AD CS RPC endpoint to reach NT AUTHORITY/SYSTEM
  • Useful for mapping privilege escalation paths on Windows web servers
Full article

Comments

This source does not provide full text. Read it at mannulinux.org.