Today we're publishing new techniques for recovering NTLM hashes from encrypted credentials protected by Windows Defender Credential Guard.
These techniques also work on victims logged on before the server was compromised.
Certipy reached 1k stars on GitHub. Let’s celebrate with a brand new version, new research, a forked BloodHound GUI with ADCS support, and many new features, for instance Schannel authentication via LDAPS, SSPI authentication, and much more!
The first blog post is here. This one covers the technical details of CVE-2022-26923 (Active Directory Domain Services Elevation of Privilege Vulnerability).
The vulnerability was patched as part of the May 2022 Security Updates from Microsoft.
research.ifcr.dk/9e098fe298f4
Happy Patch Tuesday!
Today, Microsoft patched a series of vulnerabilities that I reported a while ago. 1 is a critical Active Directory privilege escalation, and 3 are Print Spooler vulnerabilities, including a local privilege escalation.
Stay tuned for the technical details.