CVE-2023-21746, commonly known as LocalPotato, is a Windows NTLM elevation of privilege vulnerability caused by improper handling of local NTLM authentication state. The issue arises from abuse of the NTLM Type 2 Challenge message Reserved field during local authentication, where the field contains a reference to a local server context handle. By swapping context handles between a low-privileged authentication flow and a privileged authentication flow, an attacker can cause LSASS to associate the wrong security identity with an attacker-controlled session. This enables a local NTLM reflection attack in which a privileged local authentication, such as one performed by SYSTEM or another privileged service, is rebound to the attacker’s chosen target. Researchers demonstrated the flaw using SSPI-based NTLM exchanges involving InitializeSecurityContext() and AcceptSecurityContext(), coercing privileged authentication and then relaying the resulting context to local services such as SMB. In practical exploitation, this can yield arbitrary file read/write primitives and can be chained to obtain full SYSTEM privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository implements the LocalPotato NTLM reflection local privilege escalation technique as a Cobalt Strike Beacon Object File (BOF) with an Aggressor script wrapper. Structure/purpose: - localpotato.c: Main BOF implementation (single-file consolidation) with sections for COM object implementations, SSPI hook (AcceptSecurityContext), COM server initialization + DCOM trigger (“PotatoTrigger”), and two client implementations (SMB and HTTP). Entry point is the BOF-exported function `go`, which parses packed arguments, initializes COM, hooks SSPI, starts a client thread (SMBAuthenticatedFileWrite or HTTPAuthenticatedGET), triggers DCOM activation to coerce SYSTEM authentication, waits up to 30 seconds, then unhooks and cleans up. - localpotato.h: Core structures/constants and prototypes. Defines DEFAULT_CLSID and DEFAULT_COM_PORT, context structure (events, SSPI function table pointers, mode selection, SMB/HTTP parameters), and SMB2 packet structures used for manual SMB2 message crafting. - bofdefs.h + beacon.h: Cobalt Strike BOF support headers. `bofdefs.h` provides Dynamic Function Resolution (DFR) declarations/macros for Win32 APIs (KERNEL32, WS2_32, OLE32, RPCRT4, NTDLL, CRYPT32, MSVCRT, etc.) required because BOFs cannot link normally. `beacon.h` provides Beacon APIs for argument parsing and output. - localpotato.cna: Aggressor script registering the `localpotato` command, handling argument parsing, selecting the correct architecture object file, packing arguments (`bof_pack`), and executing the BOF inline. - Makefile: Builds x86 and x64 BOF object files using mingw-w64 compilers. Exploit capabilities: - Coerces a privileged (SYSTEM) DCOM/COM authentication flow and performs NTLM reflection by hooking SSPI’s AcceptSecurityContext and swapping/capturing contexts (as indicated by ctx fields and HookSSPIForDCOMReflection/UnhookSSPI). - Provides two operational post-reflection actions: 1) SMB mode: establishes an SMB2 session and performs negotiate/auth/tree connect/create/write/close to write a supplied local file to a specified destination path using the reflected authentication. 2) HTTP mode: performs an authenticated HTTP GET to a specified host and URL path using the reflected authentication. Notable fingerprintables: - Default COM port 10271 and default CLSID {854A20FB-2D44-457D-992F-EF13785D2B51}. - Network behaviors include SMB2 (likely TCP/445) and HTTP requests to runtime-specified targets. Overall, this is an operational BOF exploit module intended for use inside Cobalt Strike to achieve LPE via NTLM reflection and then leverage the elevated authentication to perform SMB file write or HTTP authenticated requests.
This repository provides a full operational exploit for a local privilege escalation (LPE) vulnerability in Microsoft Windows, known as LocalPotato (CVE-2023-21746). The exploit leverages a flaw in NTLM local authentication to gain SYSTEM-level access to SMB shares, allowing arbitrary file read/write as SYSTEM. To achieve code execution, the exploit combines this with a DLL hijacking technique targeting the StorSvc service: by writing a malicious SprintCSP.dll to a directory in the system PATH, and then triggering the SvcRebootToFlashingMode RPC method (via RpcClient), the attacker causes StorSvc (running as SYSTEM) to load and execute the attacker's DLL. The provided DLL (SprintCSP/main.c) demonstrates execution of a command as SYSTEM, but can be modified for arbitrary payloads. The repository includes detection rules (YARA, Sigma) for defenders. The structure includes two main Visual Studio projects: RpcClient (triggers the vulnerable RPC call) and SprintCSP (the malicious DLL payload). This is a weaponized, operational exploit requiring local access and is effective against unpatched Windows systems with the vulnerable configuration.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A local privilege escalation vulnerability in Microsoft Windows, allowing attackers to gain elevated privileges on a compromised system.
A local NTLM authentication context-swapping elevation-of-privilege vulnerability in Windows that can enable arbitrary file read/write and, when chained, escalation from a low-privileged user to SYSTEM.
An elevation-of-privilege vulnerability affecting Windows NTLM.
Windows NTLM authentication protocol privilege escalation vulnerability referred to as LocalPotato, used here in an attempted privilege escalation phase.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.