KRBUACBypass
This POC is inspired by James Forshaw (@tiraniddo) shared at BlackHat USA 2022 titled “Taking Kerberos To The Next Level ”
By adding a KERB-AD-RESTRICTION-ENTRY to the service ticket, but filling in a fake MachineID, we can easily bypass UAC and gain SYSTEM privileges.
[/SIZE]
KRBUACBypass.exe asktgs
KRBUACBypass.exe krbscm
[SIZE=5]Link: