Digging Deeper into Vulnerable Windows Services
ID: b9989f21-4b2b-5e21-8eb5-2a6fb74ec0c0
STIX ID: report--b9989f21-4b2b-5e21-8eb5-2a6fb74ec0c0
Feed Name: Black Hills Infosec Blog
This blog post explains two Windows local privilege escalation techniques against insecure services: (1) reconfiguring a privileged service to run a compiled C# payload via InstallUtil to bypass application whitelisting and obtain SYSTEM-level execution, and (2) placing blank DLLs matching System32 DLL names into a service directory to crash the service when restarted, enabling overwrite or reconfiguration of the service binary. The post includes compilation and sc config examples and discusses limitations and mitigation considerations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
