[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$flB1iNezL1gil0RuCOSwyB5YW0sh5SKS9bRPBSMgA30I":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},788,"How do you enumerate and verify usable COM objects for Juicy Potato?","Use the provided PowerShell script GetCLSID.ps1 to generate a list of CLSIDs from the registry, then test each one with JuicyPotato.exe in test mode (-z) using a batch script. The tool checks if the CLSID can produce a System-privileged token. Note that on some systems like Windows Server 2012, modifications to the enumeration script may be needed, as described in the [Juicy Potato Testing Analysis](\u002Fnews\u002Fwindows-local-privilege-escalation-tool-juicy-potato-testing-analysis). Verified CLSIDs for various Windows versions are maintained in the project's GitHub repository.","\u003Cp>Use the provided PowerShell script GetCLSID.ps1 to generate a list of CLSIDs from the registry, then test each one with JuicyPotato.exe in test mode (-z) using a batch script. The tool checks if the CLSID can produce a System-privileged token. Note that on some systems like Windows Server 2012, modifications to the enumeration script may be needed, as described in the [Juicy Potato Testing Analysis](\u002Fnews\u002Fwindows-local-privilege-escalation-tool-juicy-potato-testing-analysis). Verified CLSIDs for various Windows versions are maintained in the project&#39;s GitHub repository.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fwindows-local-privilege-escalation-tool-juicy-potato-testing-analysis\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-do-you-enumerate-and-verify-usable-com-objects-for-juicy-potato-1777481914891","CLSID enumeration, GetCLSID.ps1, test mode, Juicy Potato, Windows Server 2012",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},194,"Windows Local Privilege Escalation Tool Juicy Potato Testing Analysis","windows-local-privilege-escalation-tool-juicy-potato-testing-analysis","Test and analysis of Juicy Potato, a Windows local privilege escalation tool. Covers usage, limitations, and defense strategies for exploiting SeImpersonate\u002FSeAssignPrimaryToken privileges.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Juicy Potato is a local privilege escalation tool for Windows systems, extending the RottenPotatoNG tool with broader applicability conditions.\u003C\u002Fp>\u003Cp>The prerequisite for exploitation is obtaining SeImpersonate or SeAssignPrimaryToken privileges, typically used in webshell environments.\u003C\u002Fp>\u003Cp>So, what are the usage methods of Juicy Potato, and what are its limitations? This article will conduct tests and analyze the constraints based on its principles.\u003C\u002Fp>\u003Cp>Download link for Juicy Potato:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fohpe\u002Fjuicy-potato\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Implementation principles\u003C\u002Fli>\u003Cli>Extensions to RottenPotatoNG\u003C\u002Fli>\u003Cli>Methods for enumerating available COM objects\u003C\u002Fli>\u003Cli>Usage methods\u003C\u002Fli>\u003Cli>Constraints\u003C\u002Fli>\u003Cli>Defense Ideas\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Implementation Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ffoxglovesecurity.com\u002F2016\u002F09\u002F26\u002Frotten-potato-privilege-escalation-from-service-accounts-to-system\u002F\u003C\u002Fp>\u003Cp>Introduction to the implementation principle based on personal understanding\u003C\u002Fp>\u003Cp>Several key concepts to understand:\u003C\u002Fp>\u003Col>\u003Cli>When using DCOM, if connecting remotely as a service, the permissions are System, for example, the BITS service\u003C\u002Fli>\u003Cli>Using DCOM allows connecting via TCP to a local port, initiating NTLM authentication, which can be replayed\u003C\u002Fli>\u003Cli>The LocalService user has SeImpersonate and SeAssignPrimaryToken permissions by default\u003C\u002Fli>\u003Cli>With SeImpersonate permission enabled, it is possible to pass a new Token when calling CreateProcessWithToken to create a new process\u003C\u002Fli>\u003Cli>With SeAssignPrimaryToken permission enabled, it is possible to pass a new Token when calling CreateProcessAsUser to create a new process\u003C\u002Fli>\u003C\u002Fol>\u003Cp>The implementation flow of Juicy Potato is as follows:\u003C\u002Fp>\u003Ch4>1. Load COM, send a request, with System permissions\u003C\u002Fh4>\u003Cp>Attempt to load a COM object at the specified IP and port\u003C\u002Fp>\u003Cp>The COM object used by RottenPotatoNG is BITS, with CLSID {4991d34b-80a1-4291-83b6-3328366b9097}\u003C\u002Fp>\u003Cp>The available COM objects are not unique; Juicy Potato provides multiple options. For a detailed list, refer to the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fohpe\u002Fjuicy-potato\u002Fblob\u002Fmaster\u002FCLSID\u002FREADME.md\u003C\u002Fp>\u003Ch4>2. Respond to the request in step 1 and initiate NTLM authentication\u003C\u002Fh4>\u003Cp>Normally, due to insufficient permissions, the current privilege is not System, so authentication cannot succeed\u003C\u002Fp>\u003Ch4>3. For the local port, also initiate NTLM authentication with the current user's privileges\u003C\u002Fh4>\u003Cp>Since the privilege is the current user, the NTLM authentication can be successfully completed\u003C\u002Fp>\u003Cp>RottenPotatoNG uses port 135\u003C\u002Fp>\u003Cp>Juicy Potato supports specifying any local port, but RPC typically defaults to port 135, which is rarely modified\u003C\u002Fp>\u003Ch4>4. Intercept the data packets of both NTLM authentications separately, replace the data, and use NTLM relay to allow the NTLM authentication in step 1 (with System privileges) to succeed, obtaining a System-privileged Token\u003C\u002Fh4>\u003Cp>During relay, note that the NTLM Server Challenge in NTLM authentication differs and needs to be corrected\u003C\u002Fp>\u003Ch4>5. Use the System-privileged Token to create a new process\u003C\u002Fh4>\u003Cp>If SeImpersonate privilege is enabled, call CreateProcessWithToken, pass the System-privileged Token, and the created process will have System privileges\u003C\u002Fp>\u003Cp>Or\u003C\u002Fp>\u003Cp>If the SeAssignPrimaryToken privilege is enabled, calling CreateProcessAsUser with a System-privileged Token creates a process with System privileges.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For detailed explanation, refer to the previous article 'Penetration Techniques – Exploitation of Nine Windows Privileges'.\u003C\u002Fp>\u003Cp>\u003Cstrong>Key to exploitation:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The current user supports SeImpersonate or SeAssignPrimaryToken privileges.\u003C\u002Fp>\u003Cp>Users with this privilege include:\u003C\u002Fp>\u003Cul>\u003Cli>Members of the local Administrators group and local service accounts.\u003C\u002Fli>\u003Cli>Services started by the Service Control Manager.\u003C\u002Fli>\u003Cli>COM servers started by the Component Object Model (COM) infrastructure and configured to run under a specific account.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For privilege escalation, the third category is mainly targeted, commonly LocalService users, such as IIS or SQL Server users.\u003C\u002Fp>\u003Ch2>0x03 Methods for Enumerating Available COM Objects\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Juicy Potato provides methods for enumerating available COM objects, with steps as follows:\u003C\u002Fp>\u003Ch4>1. Obtain a list of available CLSIDs.\u003C\u002Fh4>\u003Cp>Use GetCLSID.ps1, available at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fohpe\u002Fjuicy-potato\u002Fblob\u002Fmaster\u002FCLSID\u002FGetCLSID.ps1\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The supporting file .\\utils\\Join-Object.ps1 must be present in the same directory during use.\u003C\u002Fp>\u003Cp>After successful execution, files CLSID.list and CLSID.csv will be generated.\u003C\u002Fp>\u003Ch4>2. Use batch processing to call juicypotato.exe to test CLSIDs one by one\u003C\u002Fh4>\u003Cp>The batch file address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fohpe\u002Fjuicy-potato\u002Fblob\u002Fmaster\u002FTest\u002Ftest_clsid.bat\u003C\u002Fp>\u003Cp>The parameters for juicypotato.exe are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>juicypotato.exe -z -l !port! -c %%i &gt;&gt; result.log\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>-z indicates test mode, only verifying the Token without using it to create a process\u003C\u002Fp>\u003Cp>-l is the port, starting at 1000 and incrementing by 1 each loop\u003C\u002Fp>\u003Cp>-c is the CLSID obtained from the file CLSID.list\u003C\u002Fp>\u003Cp>Juicy Potato has been tested on the following Windows systems:\u003C\u002Fp>\u003Cul>\u003Cli>Windows 7 Enterprise\u003C\u002Fli>\u003Cli>Windows 8.1 Enterprise\u003C\u002Fli>\u003Cli>Windows 10 Enterprise\u003C\u002Fli>\u003Cli>Windows 10 Professional\u003C\u002Fli>\u003Cli>Windows Server 2008 R2 Enterprise\u003C\u002Fli>\u003Cli>Windows Server 2012 Datacenter\u003C\u002Fli>\u003Cli>Windows Server 2016 Standard\u003C\u002Fli>\u003C\u002Ful>\u003Cp>During my testing, an error occurred when executing GetCLSID.ps1 under Server 2012, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017237753_0_aa9ec88dda.jpeg\">\u003C\u002Fp>\u003Cp>The error location is at .\\utils\\Join-Object.ps1\u003C\u002Fp>\u003Cp>Here is one modification method:\u003C\u002Fp>\u003Ch4>1. Enumerate all CLSIDs that meet the conditions\u003C\u002Fh4>\u003Cp>The PowerShell code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-PSDrive -Name HKCR -PSProvider Registry -Root HKEY_CLASSES_ROOT | Out-Null\u003Cbr>$CLSID = Get-ItemProperty HKCR:\\clsid\\* | select-object AppID,@{N='CLSID'; E={$_.pschildname}} | where-object {$_.appid -ne $null}\u003Cbr>foreach($a in $CLSID)\u003Cbr>{\u003Cbr>\tWrite-Host $a.CLSID\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>You can choose to save the results as CLSID.list\u003C\u002Fp>\u003Ch4>2. Use batch processing to call juicypotato.exe for verification one by one\u003C\u002Fh4>\u003Cp>The address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fohpe\u002Fjuicy-potato\u002Fblob\u002Fmaster\u002FTest\u002Ftest_clsid.bat\u003C\u002Fp>\u003Cp>No modifications are needed for the bat script\u003C\u002Fp>\u003Ch2>0x04 Usage Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Check the current user privileges to see if they meet the requirements\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>whoami \u002Fpriv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If the SeImpersonate privilege is enabled, the parameter for juicypotato can be -t t\u003C\u002Fp>\u003Cp>If the SeAssignPrimaryToken privilege is enabled, the parameter for juicypotato can be -t u\u003C\u002Fp>\u003Cp>If both are enabled, you can choose -t *\u003C\u002Fp>\u003Cp>If neither is enabled, then privilege escalation is not possible\u003C\u002Fp>\u003Ch3>2. Check if the default RPC port is 135\u003C\u002Fh3>\u003Cp>If modified (e.g., to 111), the juicypotato parameter can use -n 111\u003C\u002Fp>\u003Cp>If RPC is disabled on the system, privilege escalation is not necessarily impossible; the following conditions must be met:\u003C\u002Fp>\u003Cp>Find another system that allows remote RPC login with the current user's permissions. In this case, the juicypotato parameter can use -k \u003Cip>\u003C\u002Fip>\u003C\u002Fp>\u003Cp>For example, in Win7 and Win8 systems, under default configurations, allowing inbound rules for port 135 enables remote RPC login\u003C\u002Fp>\u003Cp>The command to add a firewall rule allowing inbound traffic on port 135 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall firewall add rule name=\"135\" protocol=TCP dir=in localport=135 action=allow\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Alternatively, you can choose to disable the firewall. Refer to the code for bypassing UAC to disable the firewall:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>3. Select an available CLSID based on the operating system\u003C\u002Fh3>\u003Cp>Reference list\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fohpe\u002Fjuicy-potato\u002Fblob\u002Fmaster\u002FCLSID\u002FREADME.md\u003C\u002Fp>\u003Cp>For example, for the test system Server2012, select CLSID {8BC3F05E-D86B-11D0-A075-00C04FB68820}\u003C\u002Fp>\u003Ch3>4. Choose a port not occupied by the system as the listening port\u003C\u002Fh3>\u003Cp>For example, the final parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>JuicyPotato.exe -t t -p c:\\windows\\system32\\cmd.exe -l 1111 -c {8BC3F05E-D86B-11D0-A075-00C04FB68820}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Indicates creating a process with SeImpersonate privilege enabled, listening on port 1111, using CLSID {8BC3F05E-D86B-11D0-A075-00C04FB68820}\u003C\u002Fp>\u003Ch2>0x05 Constraints\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Based on the above analysis, the constraints of Juicy Potato are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Requires support for SeImpersonate or SeAssignPrimaryToken privileges\u003C\u002Fli>\u003Cli>Enable DCOM\u003C\u002Fli>\u003Cli>Local support for RPC or remote server support for RPC with successful login\u003C\u002Fli>\u003Cli>Able to find available COM objects\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x06 Defense Strategy\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>From a defensive perspective, disabling DCOM, disabling RPC, or configuring properties for each COM object on the server is impractical\u003C\u002Fp>\u003Cp>The key to defending against Juicy Potato lies in permission control, preventing attackers from obtaining SeImpersonate or SeAssignPrimaryToken privileges\u003C\u002Fp>\u003Ch2>0x07 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>More learning materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fbugs.chromium.org\u002Fp\u002Fproject-zero\u002Fissues\u002Fdetail?id=325&amp;redir=1\u003C\u002Fp>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tests Juicy Potato, summarizes usage methods, compares it with RottenPotatoNG, analyzes principles, and identifies limitations and defense strategies\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Juicy Potato is a local privilege escalation tool for Windows systems, extending the RottenPotatoNG tool with broader applicability conditions.\u003C\u002Fp>\u003Cp>The prerequisite for exploitation is obtaining SeImpersonate or SeAssignPrimaryToken privileges, typically used in webshell environments.\u003C\u002Fp>\u003Cp>So, what are the usage methods of Juicy Potato, and what are its limitations? This article will conduct tests and analyze the constraints based on its principles.\u003C\u002Fp>\u003Cp>Download link for Juicy Potato:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fohpe\u002Fjuicy-potato\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Implementation principles\u003C\u002Fli>\u003Cli>Extensions to RottenPotatoNG\u003C\u002Fli>\u003Cli>Methods for enumerating available COM objects\u003C\u002Fli>\u003Cli>Usage methods\u003C\u002Fli>\u003Cli>Constraints\u003C\u002Fli>\u003Cli>Defense Ideas\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Implementation Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ffoxglovesecurity.com\u002F2016\u002F09\u002F26\u002Frotten-potato-privilege-escalation-from-service-accounts-to-system\u002F\u003C\u002Fp>\u003Cp>Introduction to the implementation principle based on personal understanding\u003C\u002Fp>\u003Cp>Several key concepts to understand:\u003C\u002Fp>\u003Col>\u003Cli>When using DCOM, if connecting remotely as a service, the permissions are System, for example, the BITS service\u003C\u002Fli>\u003Cli>Using DCOM allows connecting via TCP to a local port, initiating NTLM authentication, which can be replayed\u003C\u002Fli>\u003Cli>The LocalService user has SeImpersonate and SeAssignPrimaryToken permissions by default\u003C\u002Fli>\u003Cli>With SeImpersonate permission enabled, it is possible to pass a new Token when calling CreateProcessWithToken to create a new process\u003C\u002Fli>\u003Cli>With SeAssignPrimaryToken permission enabled, it is possible to pass a new Token when calling CreateProcessAsUser to create a new process\u003C\u002Fli>\u003C\u002Fol>\u003Cp>The implementation flow of Juicy Potato is as follows:\u003C\u002Fp>\u003Ch4>1. Load COM, send a request, with System permissions\u003C\u002Fh4>\u003Cp>Attempt to load a COM object at the specified IP and port\u003C\u002Fp>\u003Cp>The COM object used by RottenPotatoNG is BITS, with CLSID {4991d34b-80a1-4291-83b6-3328366b9097}\u003C\u002Fp>\u003Cp>The available COM objects are not unique; Juicy Potato provides multiple options. For a detailed list, refer to the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fohpe\u002Fjuicy-potato\u002Fblob\u002Fmaster\u002FCLSID\u002FREADME.md\u003C\u002Fp>\u003Ch4>2. Respond to the request in step 1 and initiate NTLM authentication\u003C\u002Fh4>\u003Cp>Normally, due to insufficient permissions, the current privilege is not System, so authentication cannot succeed\u003C\u002Fp>\u003Ch4>3. For the local port, also initiate NTLM authentication with the current user's privileges\u003C\u002Fh4>\u003Cp>Since the privilege is the current user, the NTLM authentication can be successfully completed\u003C\u002Fp>\u003Cp>RottenPotatoNG uses port 135\u003C\u002Fp>\u003Cp>Juicy Potato supports specifying any local port, but RPC typically defaults to port 135, which is rarely modified\u003C\u002Fp>\u003Ch4>4. Intercept the data packets of both NTLM authentications separately, replace the data, and use NTLM relay to allow the NTLM authentication in step 1 (with System privileges) to succeed, obtaining a System-privileged Token\u003C\u002Fh4>\u003Cp>During relay, note that the NTLM Server Challenge in NTLM authentication differs and needs to be corrected\u003C\u002Fp>\u003Ch4>5. Use the System-privileged Token to create a new process\u003C\u002Fh4>\u003Cp>If SeImpersonate privilege is enabled, call CreateProcessWithToken, pass the System-privileged Token, and the created process will have System privileges\u003C\u002Fp>\u003Cp>Or\u003C\u002Fp>\u003Cp>If the SeAssignPrimaryToken privilege is enabled, calling CreateProcessAsUser with a System-privileged Token creates a process with System privileges.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For detailed explanation, refer to the previous article 'Penetration Techniques – Exploitation of Nine Windows Privileges'.\u003C\u002Fp>\u003Cp>\u003Cstrong>Key to exploitation:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The current user supports SeImpersonate or SeAssignPrimaryToken privileges.\u003C\u002Fp>\u003Cp>Users with this privilege include:\u003C\u002Fp>\u003Cul>\u003Cli>Members of the local Administrators group and local service accounts.\u003C\u002Fli>\u003Cli>Services started by the Service Control Manager.\u003C\u002Fli>\u003Cli>COM servers started by the Component Object Model (COM) infrastructure and configured to run under a specific account.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For privilege escalation, the third category is mainly targeted, commonly LocalService users, such as IIS or SQL Server users.\u003C\u002Fp>\u003Ch2>0x03 Methods for Enumerating Available COM Objects\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Juicy Potato provides methods for enumerating available COM objects, with steps as follows:\u003C\u002Fp>\u003Ch4>1. Obtain a list of available CLSIDs.\u003C\u002Fh4>\u003Cp>Use GetCLSID.ps1, available at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fohpe\u002Fjuicy-potato\u002Fblob\u002Fmaster\u002FCLSID\u002FGetCLSID.ps1\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The supporting file .\\utils\\Join-Object.ps1 must be present in the same directory during use.\u003C\u002Fp>\u003Cp>After successful execution, files CLSID.list and CLSID.csv will be generated.\u003C\u002Fp>\u003Ch4>2. Use batch processing to call juicypotato.exe to test CLSIDs one by one\u003C\u002Fh4>\u003Cp>The batch file address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fohpe\u002Fjuicy-potato\u002Fblob\u002Fmaster\u002FTest\u002Ftest_clsid.bat\u003C\u002Fp>\u003Cp>The parameters for juicypotato.exe are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>juicypotato.exe -z -l !port! -c %%i &gt;&gt; result.log\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>-z indicates test mode, only verifying the Token without using it to create a process\u003C\u002Fp>\u003Cp>-l is the port, starting at 1000 and incrementing by 1 each loop\u003C\u002Fp>\u003Cp>-c is the CLSID obtained from the file CLSID.list\u003C\u002Fp>\u003Cp>Juicy Potato has been tested on the following Windows systems:\u003C\u002Fp>\u003Cul>\u003Cli>Windows 7 Enterprise\u003C\u002Fli>\u003Cli>Windows 8.1 Enterprise\u003C\u002Fli>\u003Cli>Windows 10 Enterprise\u003C\u002Fli>\u003Cli>Windows 10 Professional\u003C\u002Fli>\u003Cli>Windows Server 2008 R2 Enterprise\u003C\u002Fli>\u003Cli>Windows Server 2012 Datacenter\u003C\u002Fli>\u003Cli>Windows Server 2016 Standard\u003C\u002Fli>\u003C\u002Ful>\u003Cp>During my testing, an error occurred when executing GetCLSID.ps1 under Server 2012, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017237753_0_aa9ec88dda-1.jpeg\">\u003C\u002Fp>\u003Cp>The error location is at .\\utils\\Join-Object.ps1\u003C\u002Fp>\u003Cp>Here is one modification method:\u003C\u002Fp>\u003Ch4>1. Enumerate all CLSIDs that meet the conditions\u003C\u002Fh4>\u003Cp>The PowerShell code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-PSDrive -Name HKCR -PSProvider Registry -Root HKEY_CLASSES_ROOT | Out-Null\u003Cbr>$CLSID = Get-ItemProperty HKCR:\\clsid\\* | select-object AppID,@{N='CLSID'; E={$_.pschildname}} | where-object {$_.appid -ne $null}\u003Cbr>foreach($a in $CLSID)\u003Cbr>{\u003Cbr>\tWrite-Host $a.CLSID\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>You can choose to save the results as CLSID.list\u003C\u002Fp>\u003Ch4>2. Use batch processing to call juicypotato.exe for verification one by one\u003C\u002Fh4>\u003Cp>The address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fohpe\u002Fjuicy-potato\u002Fblob\u002Fmaster\u002FTest\u002Ftest_clsid.bat\u003C\u002Fp>\u003Cp>No modifications are needed for the bat script\u003C\u002Fp>\u003Ch2>0x04 Usage Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Check the current user privileges to see if they meet the requirements\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>whoami \u002Fpriv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If the SeImpersonate privilege is enabled, the parameter for juicypotato can be -t t\u003C\u002Fp>\u003Cp>If the SeAssignPrimaryToken privilege is enabled, the parameter for juicypotato can be -t u\u003C\u002Fp>\u003Cp>If both are enabled, you can choose -t *\u003C\u002Fp>\u003Cp>If neither is enabled, then privilege escalation is not possible\u003C\u002Fp>\u003Ch3>2. Check if the default RPC port is 135\u003C\u002Fh3>\u003Cp>If modified (e.g., to 111), the juicypotato parameter can use -n 111\u003C\u002Fp>\u003Cp>If RPC is disabled on the system, privilege escalation is not necessarily impossible; the following conditions must be met:\u003C\u002Fp>\u003Cp>Find another system that allows remote RPC login with the current user's permissions. In this case, the juicypotato parameter can use -k \u003Cip>\u003C\u002Fip>\u003C\u002Fp>\u003Cp>For example, in Win7 and Win8 systems, under default configurations, allowing inbound rules for port 135 enables remote RPC login\u003C\u002Fp>\u003Cp>The command to add a firewall rule allowing inbound traffic on port 135 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall firewall add rule name=\"135\" protocol=TCP dir=in localport=135 action=allow\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Alternatively, you can choose to disable the firewall. Refer to the code for bypassing UAC to disable the firewall:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>3. Select an available CLSID based on the operating system\u003C\u002Fh3>\u003Cp>Reference list\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fohpe\u002Fjuicy-potato\u002Fblob\u002Fmaster\u002FCLSID\u002FREADME.md\u003C\u002Fp>\u003Cp>For example, for the test system Server2012, select CLSID {8BC3F05E-D86B-11D0-A075-00C04FB68820}\u003C\u002Fp>\u003Ch3>4. Choose a port not occupied by the system as the listening port\u003C\u002Fh3>\u003Cp>For example, the final parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>JuicyPotato.exe -t t -p c:\\windows\\system32\\cmd.exe -l 1111 -c {8BC3F05E-D86B-11D0-A075-00C04FB68820}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Indicates creating a process with SeImpersonate privilege enabled, listening on port 1111, using CLSID {8BC3F05E-D86B-11D0-A075-00C04FB68820}\u003C\u002Fp>\u003Ch2>0x05 Constraints\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Based on the above analysis, the constraints of Juicy Potato are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Requires support for SeImpersonate or SeAssignPrimaryToken privileges\u003C\u002Fli>\u003Cli>Enable DCOM\u003C\u002Fli>\u003Cli>Local support for RPC or remote server support for RPC with successful login\u003C\u002Fli>\u003Cli>Able to find available COM objects\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x06 Defense Strategy\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>From a defensive perspective, disabling DCOM, disabling RPC, or configuring properties for each COM object on the server is impractical\u003C\u002Fp>\u003Cp>The key to defending against Juicy Potato lies in permission control, preventing attackers from obtaining SeImpersonate or SeAssignPrimaryToken privileges\u003C\u002Fp>\u003Ch2>0x07 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>More learning materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fbugs.chromium.org\u002Fp\u002Fproject-zero\u002Fissues\u002Fdetail?id=325&amp;redir=1\u003C\u002Fp>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tests Juicy Potato, summarizes usage methods, compares it with RottenPotatoNG, analyzes principles, and identifies limitations and defense strategies\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",759,"Onedaysec",6,"published","2026-02-02T07:38:21.199Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Juicy Potato Windows Privilege Escalation Tool Testing & Analysis","Juicy Potato, Windows privilege escalation, local privilege escalation, SeImpersonate, SeAssignPrimaryToken, COM objects, RottenPotatoNG, penetration testing, security tools",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46,47],790,789,787,786,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.497Z","2026-07-23T16:02:06.450Z","draft","2026-07-23T16:14:45.737Z"]