
PowerShell exploit for CVE-2024-0670 that abuses CheckMK Agent MSI repair to escalate privileges to SYSTEM on the NanoCorp Hack The Box machine.
This repository contains a PowerShell script used to exploit CVE-2024-0670 on the NanoCorp machine from Hack The Box. The vulnerability allows a low-privileged user to abuse the CheckMK Windows Agent MSI repair functionality and execute arbitrary commands with SYSTEM privileges.
Note: This exploit was developed for the NanoCorp Hack The Box machine and may require modification before use in other environments.
Disclaimer: This repository is provided for educational purposes and authorized security testing only. Use it only on systems you own or have explicit permission to test.
Upload RunasCs.exe — required to run the exploit as the web_svc user.
Execute the script as the web_svc user:
.\RunasCs.exe "web_svc" "YourWebSvcPassword" "powershell -ExecutionPolicy Bypass -File C:\ProgramData\CVE-2024-0670-NanoCorp.ps1"
Wait for the MSI repair process to complete. This may take a few minutes.
Once finished, the script will output credentials for the newly created local administrator account:
A new User added as administrator with the following credentials: dfdxarjy Password123@
Verify successful privilege escalation:
nxc smb nanocorp.htb -u "dfdxarjy" -p "Password123@" -k
Expected output:
[+] nanocorp.htb\dfdxarjy:Password123@ (Pwn3d!)
The vulnerability allows a low-privileged user (such as web_svc) to escalate privileges to NT AUTHORITY\SYSTEM by abusing the Windows Installer repair functionality used by the CheckMK Agent.
The script performs the following actions:
C:\Windows\Temp containing commands to create a local user account.msiexec /fa.Administrators group.