
PoC for CVE-2019-12476, a Windows authentication bypass in ManageEngine ADSelfService Plus that provides an unauthenticated SYSTEM shell via crafted password reset flow.
ADSelfService Plus version 4.3.3 PoC for an authentication bypass on Windows 10.
Affects all versions of Windows
PoC Video
Steps to repoduce
Update to the latest version; current latest version is 5.0.6
The same exploit was verified to work in another vendor, so give it a shot if you're using a self service password reset app in your organazation.
I was able to bypass the patch 5.0.6 but it's very unstable once I find a stable way of automatating the exploit it will be released.
scottjw - For automating the exploit.