HTB · Medium
HTB Pov: ASP.NET ViewState Deserialization and SeDebugPrivilege Abuse
A path traversal on an IIS endpoint leaks the ASP.NET machineKey, enabling ViewState deserialization RCE. Credential extraction from a PSCredential XML file pivots to a user with SeDebugPrivilege, abused to migrate into a SYSTEM process.