
PrintNightMare LPE提权漏洞的CS 反射加载插件。开箱即用、通过内存加载、混淆加载的驱动名称来ByPass Defender/EDR。
CS reflective loading plugin for PrintNightMare LPE privilege escalation vulnerability. Out-of-the-box, memory loading, obfuscated driver name loading to bypass Defender/EDR.
Disclaimer:
This project is only for learning and communication, please use it cautiously within a reasonable scope of authorization.
Download this project:
Cobalt Strike load the plugin

Usage:
> print_night_mare_lpe dllpath
> elevate -> PrintNightMare-1675 -> choose your listener -> exploit
Default WinSer 2009 environment (Windows Defender), WinServer 2016 (Windows Defender)
Custom DLL path:

elevate module:

If it returns 0, it means it can be exploited successfully. The elevate implementation obfuscates the driver name, which may be unstable. Try multiple times or use
print_night_mare_lpe dllpath. Currently only tested on 64-bit, the elevate module also only supports 64-bit. For 32-bit, it is recommended to useprint_night_mare_lpe. This project is just for fun, enjoy..
Update the system to the latest version in a timely manner.