1. Exploiting MS15-076 (CVE-2015-2370) netspi.com | 漏洞 | 2015-08-12 00:00 | 原文 ↗ | #privilege-escalation | #windows | #ntlm-reflection | #symlink 利用 James Forshaw 发现的 MS15-076(CVE-2015-2370)DCOM/RPC NTLM 反射漏洞,结合 junction 与符号链接技巧将受限的文件写入升级为对任意特权路径(如 System32)的写入,实现本地提权。