xsspresso
xsspresso
Tags/ ESC4

ESC4

2 writeups tagged with ESC4

MiscEasyWindows

HTB — Fluffy

CVE-2025-24071 abuses .searchConnector-ms files to capture NTLMv2 hashes. Relay attack and ADCS ESC4 escalate to Domain Admin.

#NTLM Relay#ADCS#CVE-2025-24071
May 28, 2025HackTheBox
ADMediumWindows

HTB — EscapeTwo

MSSQL with xp_cmdshell after credential spraying. ADCS ESC4 template modification for certificate impersonation to gain Domain Admin.

#AD#MSSQL#ADCS
Jan 13, 2025HackTheBox