#
gMSA
2 posts
TombWatcher — AD Privilege Chain to ESC15 (CVE-2024-49019) Domain Takeover
A five-hop BloodHound chain — WriteSPN → Kerberoast → gMSA dump → password resets → WinRM — leads to a deleted AD account holding ESC15 (CVE-2024-49019) rights on an ADCS template, ultimately yielding Domain Admin via PassTheCert over Schannel.
HTB Logging: Credential Exposure → Shadow Credentials → DLL Injection → WSUS Poisoning
Starting with a low-privileged user, SMB enumeration reveals hardcoded credentials in a log file. Password pattern inference leads to an updated credential. GenericWrite over a gMSA enables Shadow Credentials and WinRM access. DLL injection via a scheduled task gives lateral movement, and WSUS poisoning combined with ADIDNS spoofing and ADCS certificate abuse yields SYSTEM.