We did it again with #LocalPotato!
A not-so-common NTLM reflection attack allowing for arbitrary read/write. Basically EoP from user to SYSTEM.
Tracked as #CVE-2023-21746 - Windows NTLM EoP
Soon more details --> http://localpotato.com
cc
@splinter_code
www.localpotato.com

@decoder_it @splinter_code if you would have found this a few months later, this would have been a "forever day" vuln in win7, win8 and win2k8r2 😄