logo

Bypass NTLM Message Integrity Check – Drop the MIC

ID: 5c042d91-73f9-56df-bd71-450c379b92a4

STIX ID: report--5c042d91-73f9-56df-bd71-450c379b92a4

Feed Name: Black Hills Infosec Blog

Threat Score
75/100

Date Published: 2024-02-01

Date Updated: 2026-04-27

Author: BHIS

...
...

This technical write-up demonstrates how an attacker can exploit CVE-2019-1040 to remove the NTLM Message Integrity Code and relay SMB authentications to LDAPS, create domain computer accounts using default machine account quotas, and escalate to Domain Admin by creating delegated computer objects and requesting service tickets; it includes step-by-step commands (ntlmrelayx, Responder, Coercer, Impacket getST) and defensive recommendations such as enabling SMB signing, disabling LLMNR/NetBIOS/NTLM, and patching affected systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.