SANS ISC Diary - Desktop.ini as a post-exploitation tool

16-03-2020 / In categories SANS ISC, News, 2020

Microsoft, Post-exploitation, Red teaming, SANS, Vulnerability, Windows

Translation: CS

A Diary of mine was published today on the SANS Internet Storm Center. In this one, we take a look at a vulnerability in the way Windows handles desktop.ini files, which makes it possible to use them as an interesting post-exploitation tool.