MS14-068(CVE-2014-6324)
Kerberos 校验和漏洞
EXP/POC:
https://github.com/abatchy17/WindowsExploits/tree/master/MS14-068
CVE-2020-1472
Netlogon特权提升漏洞
EXP/POC:
https://github.com/blackarrowsec/redteam-research/tree/master/CVE-2020-1472
CVE-2021-42287&42278
Windows域服务权限提升漏洞
https://nvd.nist.gov/vuln/detail/CVE-2021-42287
https://nvd.nist.gov/vuln/detail/CVE-2021-42278
EXP/POC:
https://github.com/WazeHell/sam-the-admin
https://github.com/cube0x0/noPac
CVE-2019-1040
Microsoft Windows NTLM认证漏洞
https://nvd.nist.gov/vuln/detail/CVE-2019-1040
https://paper.seebug.org/962/
EXP/POC:
CVE-2018-8581
Microsoft Exchange任意用户伪造漏洞
EXP/POC:
CVE-2020-0688
Microsoft Exchange 反序列化RCE
EXP/POC:
CVE-2021-1675
Windows Print Spooler权限提升漏洞
EXP/POC:
CVE-2021-26855/CVE-2021-27065
Exchange ProxyLogon远程代码执行漏洞
https://nvd.nist.gov/vuln/detail/CVE-2021-26855
https://nvd.nist.gov/vuln/detail/CVE-2021-27065
EXP/POC:
CVE-2020-17144
Microsoft Exchange 远程代码执行漏洞
EXP/POC:
CVE-2020-16875
Microsoft Exchange 远程代码执行漏洞
EXP/POC:
CVE-2021-34473
Exchange ProxyShell SSRF
EXP/POC:
CVE-2021-33766
Exchange ProxyToken 信息泄露漏洞
EXP/POC: