SharpSecDump icon indicating copy to clipboard operation
SharpSecDump copied to clipboard

Move temp storage of reg hives to %TEMP%

Open bugch3ck opened this issue 2 years ago • 0 comments

Storing the SAM and SECURITY hive in a folder where local unprivileged users can read them results in a privilege escalation vulnerability.

https://disobey.fi/2023/profile/finding_vulnerabilities_in_offensive

bugch3ck avatar Feb 16 '23 18:02 bugch3ck