logo

Will WebClient Start

ID: 868dda74-2874-5f42-be2c-15202d744a4d

STIX ID: report--868dda74-2874-5f42-be2c-15202d744a4d

Feed Name: SpecterOps Blog

Date Published: 2025-08-19

Date Updated: 2026-04-30

Author: Steven Flores

...
...

This research analyzes if a low-privileged user can remotely start the Windows WebClient service to enable targeted NTLM relay, mapping the full trigger path from MPR/davclnt’s ETW event through the UBPM ETW consumer, WNF signaling, and services.exe, and testing EFS RPC-based approaches across Windows 10/11. It finds that while WebClient can be started locally by medium-integrity users (e.g., via davclnt-triggered ETW) and by admins/SYSTEM, remote low-privileged activation via RPC is prevented by UBPM’s security descriptor; Windows 11’s EFS changes further reduce viable paths. A PoC toolkit is provided, and the practical takeaway is that remote low-priv start is “almost but no,” reinforcing reliance on controls like SMB signing, LDAP signing/channel binding/EPA, and service hardening.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.