E-Ink News Daily

Back to list

Privilege escalation from IIS AppPool to NT Authority/SYSTEM

This article demonstrates a privilege escalation technique from IIS AppPool o NT Authority/SYSTEM in an Active Directory environment without relying on Potato-family exploits. The core insight is that when an IIS AppPool identity accesses a network resource, Windows silently elevates the identity to the host machine account, which the author abuses via the AD CS RPC endpoint.

Background

IIS AppPool identities run with limited privileges, making them a common foothold for attackers who achieve RCE on IIS-hosted applications. Active Directory Certificate Services (AD CS) is frequently leveraged in lateral movement and privilege escalation scenarios within Windows domains.

Source
Lobsters
Published
Aug 31, 2026 at 08:36 PM
Score
7.0 / 10