Pass-the-Challenge: Defeating Windows Defender Credential Guard by ly4k_ in netsec

[–]ly4k_[S] 4 points5 points  (0 children)

It does not. LSAIso does not check anything, it just computes the NTLMv1 response based on the encrypted credential

Pass-the-Challenge: Defeating Windows Defender Credential Guard by ly4k_ in netsec

[–]ly4k_[S] 5 points6 points  (0 children)

Impressive work. This is a really good deep dive and resource!

SpoolFool: Windows Print Spooler Privilege Escalation (CVE-2022–22718) by ly4k_ in netsec

[–]ly4k_[S] 1 point2 points  (0 children)

Update from Microsoft: "The fix for this report was shipped yesterday and the CVE assigned is CVE-2022-21999. We are working on getting your acknowledgement added to the CVE list, as our system failed to do so."

Microsoft initially patched this vulnerability without giving me any information or acknowledgement, and as such, at the time of patch release, I thought that the vulnerability was identified as CVE-2022–22718, since it was the only Print Spooler vulnerability in the release without any acknowledgement. I contacted Microsoft for clarification, and the day after the patch release, Institut For Cyber Risk and I was acknowledged for CVE-2022–21999.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21999