Skip to content

Conversation

mblzk
Copy link

@mblzk mblzk commented Jun 17, 2025

Added a write.exe abuse to execute arbitrary binary through registry values.

Short analysis here: https://gist.github.com/mblzk/b8c5ff7c2bd0fb2b385cc2fdd119874b

Added a write.exe abuse to execute arbitrary binary through registry values
@mblzk mblzk requested a review from a team as a code owner June 17, 2025 23:03
updated with providing arguments through registry and execution of remote binaries through UNC paths
@mblzk
Copy link
Author

mblzk commented Jun 18, 2025

Expanded the initial analysis a bit.
Based on the findings, updated the .yml with providing arguments through registry and execution of remote binaries through UNC paths

mblzk added 2 commits June 18, 2025 16:26
added quotes around problematic lines
apparently single quotes are better
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant