logo

Is TLS more secure? The WinRMS case.

ID: a8da4a2f-24d3-571f-bd92-422aed0c933b

STIX ID: report--a8da4a2f-24d3-571f-bd92-422aed0c933b

Feed Name: SensePost Blog

Threat Score
45/100

Date Published: 2025-04-14

Date Updated: 2026-04-30

...
...

This research demonstrates a PoC NTLM relay to WinRM over HTTPS (WinRMS) that can lead to remote code execution in environments allowing NTLMv1 or with Channel Binding misconfigured; the post covers WinRM protocol details, an NTLMRelayX module, real-world caveats, and mitigation (enable CbtHardeningLevel="Strict").

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.