Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-21752 — Proof-of-concept exploit for CVE-2023-21752, an arbitrary file delete vulnerability in Windows Backup service, with two variants including privilege escalation to elevated shell. | Kitploit
Tools/GitHubGitHub/wh04m1001/cve-2023-21752
Privilege EscalationVulnerability AnalysisExploitationPenetration TestingBinary Exploitation
GitHubwh04m1001/cve-2023-21752

CVE-2023-21752

Proof-of-concept exploit for CVE-2023-21752, an arbitrary file delete vulnerability in Windows Backup service, with two variants including privilege escalation to elevated shell.

View Repository
3266513 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-21752

PoC for arbitrary file delete vulnerability in Windows Backup service.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21752

This repo contains two exploits:

v1 - Just perform file delete of user choice

v2 - Tries to abuse arb delete to spawn elevated cmd shell (not very stable probably need to run it couple of times, better work on phisycal machine)

https://user-images.githubusercontent.com/44291883/211601142-c04534e5-f718-478d-b91a-65d6a4f06080.mp4

Timeline

  • 07/07/2022 - Vulnerability reported to MSRC
  • 08/10/2022 - MSRC confirmed vulnerability
  • 08/12/2022 - Bounty awarded
  • 01/10/2023 - Patch released
Download Tool