KRBUACBypass Versions Save

UAC Bypass By Abusing Kerberos Tickets


9 months ago

Now let's take a look at the running effect, as shown in the figure below. First request a ticket for the HOST service of the current server through the asktgs function, and then create a system service through krbscm to gain the SYSTEM privilege.
