DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Privilege escalation from IIS AppPool to NT Authority/SYSTEM via AD CS RPC endpoint

Quality: 8/10 Relevance: 9/10

Summary

A detailed blog post describing a Windows privilege escalation chain from IIS AppPool to the machine account on a domain via AD CS RPC endpoint. It explains how the IIS identity can be silently elevated to the machine account, enabling certificate-based TGT acquisition and S4U2Self impersonation to gain local Administrator access. The content includes step-by-step commands and screenshots, highlighting defensive considerations for AD CS abuse.

🚀 Service construit par Johan Denoyer