module

Windows SYSTEM Escalation via KiTrap0D

Disclosed
2010-01-19
Created
2018-05-30

Description

This module will create a new session with SYSTEM privileges via the
KiTrap0D exploit by Tavis Ormandy. If the session in use is already
elevated then the exploit will not run. The module relies on kitrap0d.x86.dll,
and is not supported on x64 editions of Windows.

Authors

Tavis Ormandy
HD Moore
Pusscat
OJ Reeves

Platform

Windows

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:


msf > use exploit/windows/local/ms10_015_kitrap0d
msf exploit(ms10_015_kitrap0d) > show targets
...targets...
msf exploit(ms10_015_kitrap0d) > set TARGET < target-id >
msf exploit(ms10_015_kitrap0d) > show options
...show and set options...
msf exploit(ms10_015_kitrap0d) > exploit

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.