Skip to content

Create write.yml#440

Merged
wietze merged 6 commits intoLOLBAS-Project:masterfrom
mblzk:write-exe-patch
Mar 16, 2026
Merged

Create write.yml#440
wietze merged 6 commits intoLOLBAS-Project:masterfrom
mblzk:write-exe-patch

Conversation

@mblzk
Copy link
Contributor

@mblzk mblzk commented Jun 17, 2025

Added a write.exe abuse to execute arbitrary binary through registry values.

Short analysis here: https://gist.github.com/mblzk/b8c5ff7c2bd0fb2b385cc2fdd119874b

Added a write.exe abuse to execute arbitrary binary through registry values
@mblzk mblzk requested a review from a team as a code owner June 17, 2025 23:03
updated with providing arguments through registry and execution of remote binaries through UNC paths
@mblzk
Copy link
Contributor Author

mblzk commented Jun 18, 2025

Expanded the initial analysis a bit.
Based on the findings, updated the .yml with providing arguments through registry and execution of remote binaries through UNC paths

mblzk added 2 commits June 18, 2025 16:26
added quotes around problematic lines
apparently single quotes are better
@wietze
Copy link
Member

wietze commented Mar 16, 2026

Hey nice find. Just to note, write.exe no longer exists in Windows 24H2 onwards.

Copy link
Member

@wietze wietze left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Even though it doesn't work on modern Windows 11 any more, adding for legacy systems. Ty.

@wietze wietze merged commit c39a24f into LOLBAS-Project:master Mar 16, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants