Privilege Escalation — Unquoted Service Path

Walkthrough in exploiting unquoted service path on Windows

  1. Get initial foothold

2. Check all services its path and start mode configuration

3. Display access control list for unquoted services

4. Create the exploit

5. Start a listener on Kali

6. Place the exploit .exe file in the unquoted service directory

7. Start the service

8. Confirm successful privilege escalation

