logo

ACE to RCE

ID: 70a3b9a9-ca99-5658-94be-6097f81eba8c

STIX ID: report--70a3b9a9-ca99-5658-94be-6097f81eba8c

Feed Name: SensePost Blog

Date Published: 2020-07-24

Date Updated: 2026-04-30

...
...

This write-up demonstrates a technique to abuse Active Directory GenericWrite ACE misconfigurations to execute attacker-controlled payloads at RDP logon by setting per-user Remote Desktop Environment attributes used by the legacy Remote Connection Manager (RCM). It details discovery methods (PowerView, BloodHound, RSAT), attribute manipulation via ADSI/IADsTSUserEx, payload creation (PowerShell compiled with PS2EXE), delivery over SMB, and optional credential capture through RDS profile/home folder paths, and concludes with mitigations including disabling RCM (fQueryUserConfigFromDC), restricting/monitoring SMB, auditing ACL changes, and detecting EventID 1060.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.