HTB Writeup – TombWatcher
Posted on 2025-06-08
Classic AD lateral and privesc with ESC15 / ESC3
CVE-2025-24071 to spoof Windows File Explorer & ESC16 in ADCS
Privilege Escalation practise in a Windows Active Directory
Steal memory from libc to hijack symbol resolution logic for RCE
CVE-2024-52301 to alter Laravel environment and Linux ENV injection
Hijack from the inside—abuse internal GOT/PLT in modern glibc