HOW TO: Windows Privilege Escalation via Insecure MSI Packages

preview_player
Показать описание
Be better than yesterday -

In this video, we will be going through two articles on discovering privilege escalation vulnerabilities on Windows computer via MSI packages, specifically through the MSI repair operations.

The first article shared was published in Mandiant back in July 2023 whereby they were able to identify zero days vulnerabilities on the Atera software, resulting in a privilege escalation.

The second article shared was published in October 2023 just earlier this month, whereby the author explores deeper on the issue highlighted by Mandiant, and was able to identify more than 30(!) privilege escalation vulnerabilities across several different vendors and security products!

Get a CVE under your name by looking for privilege escalation vulnerabilities on Windows system after learning and understanding the common pitfalls of MSI packages!

References used:

DISCLAIMER:
All content posted on this Youtube channel is SOLELY FOR Educational and Awareness purposes ONLY. Any actions and/or activities related to the material presented in this Youtube channel is entirely YOUR responsibility.

We DO NOT promote, support, encourage any illegal activities such as hacking, and we WILL NOT BE HELD responsible in the event of any misuse and abuse of the content resulting in any criminal charges.

FREE Introductory to Phishing course on Udemy:

Stay connected:

Gemini Security Awesome Hacking T-Shirts - Support the channel:

Looking to donate?
BTC: 19HiqQ2Qw83mxK9dcdoWb8VfAcsNgmp52k
Рекомендации по теме
Комментарии
Автор

i wanna read the article right now, that so interesting, u are amazing

tlykuyiyhaa
Автор

hi bro, can you also make videos on other windows privilege escalation techniques..im enjoying ur videos man

sscoconut
Автор

do you have to install the software first, also show us to use it in addition to a loader.

mnageh-bomm
Автор

Strange, I tested it on mine here with the same software and same version and it doesn't work.

Maybe Windows should be at some specific version? Mine at the moment is win10 22H2 19045.2006 and it's not working.

jhnZRA
Автор

your videos are amazing, by anychance could you do a video on how to crypt exe files so it can bypass windows defender atleast maybe uaing quasar rat or smt thanks ❤

theblackssvipssvzy
Автор

Huge fan bro keep up the work 💪 🙌. By chance do you have a discord server where we could communicate with you or at least try to support you work

tylerforbes