EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesEasy

A penetration tester is evaluating a Windows server. They aim to exploit a misconfiguration to gain elevated privileges. During their reconnaissance, they discover that a scheduled task is running with 'SYSTEM' privileges, executing a script from a world-writable directory. Which of the following attack techniques would be most effective for privilege escalation in this scenario?

  1. APass-the-Hash attack
  2. BService Path Hijacking
  3. CScheduled Task Abuse
  4. DDLL Side-Loading
Show answer & explanation

Correct answer: C. Scheduled Task Abuse

The scenario explicitly describes a scheduled task running with high privileges from a world-writable directory. This setup is a classic vulnerability that can be exploited by replacing the legitimate script with a malicious one, leading to privilege escalation.

Why the other options are wrong

  • A. Pass-the-Hash is used to authenticate to other systems using NTLM hashes, not directly for local privilege escalation via misconfigured scheduled tasks.
  • B. Service Path Hijacking exploits misconfigured service executable paths, often due to unquoted service paths, which is different from a scheduled task executing a script.
  • D. DLL Side-Loading involves placing a malicious DLL in a directory where an application expects to load a legitimate DLL, which is not the primary vulnerability described here.

Scheduled Task Abuse

Exploiting misconfigured scheduled tasks on a system to execute malicious code with elevated privileges, typically by replacing the legitimate script or executable.

  • Often involves tasks running with SYSTEM or administrator privileges.
  • Vulnerable if the task's executable path is writable by low-privileged users.
  • Common in Windows environments, but also applicable to cron jobs in Linux.

Memory trick: Elevate your access, bypass the gate, exploit the weak link, seal your fate.

More System Hacking Phases and Attack Techniques questions