Binary Paths

Overview

Services sometimes have executables attached to them. If we have the right permissions to the service then we can change the binary path (executable file) to a malicious one.

Exploitation using PowerUp

Run PowerUp on machine

. .\PowerUp.ps1
Invoke-AllChecks
TCM Windows Priv Esc on Try Hack Me

Change the binary path

Start service

Exploitation via Accesschk64

Check for services with write permissions

TCM Windows Priv Esc on Try Hack Me
TCM Windows Priv Esc on Try Hack Me

Query the service

TCM Windows Priv Esc on Try Hack Me

Changing the binary path is the same as the last method

Last updated

Was this helpful?