New Training: Windows Localhost Vulnerabilities, Attacks, and Tools

In this 6-video skill, CBT Nuggets trainer Bob Salmans explores the local vulnerabilities within Windows that can be used to perform privilege escalation and gain administrative permissions on Windows hosts. Watch this new cybersecurity training.
Watch the full course: CompTIA PenTest+
This training includes:
6 videos
55 minutes of training
You’ll learn these topics in this skill:
Windows Privilege Escalation Pt.1
Windows Privilege Escalation Pt.2
Getting a Windows Shell
Windows Local Host Enumeration
Windows Unquoted Service Path Vulnerability
Windows Local Exploit Privilege Escalation
How to Find Existing, Un-Patched Windows 10 Exploits
Penetration testing for InfoSec engineers is a constantly evolving discipline. Though many of the theories and tools used by pentesters don't progress quickly, the exploits in IT systems do. So, it's prudent for pentesters to stay on top of the latest discovered exploits all the time.
This is especially important for IT departments managing a lot of Windows machines. New, local exploits are constantly being found for Windows 10. It's very much a cat and mouse game. As new exploits are discovered, Microsoft quickly patches them. So, attack vectors for Windows 10 are constantly moving targets.
One of the best tools pentesters can use to find information for existing exploits in Windows 10 is by using the CVE system. The CVE system is a system managed by a non-profit entity that assigns case instances, information, and severity ratings for exploits for applications and hardware devices. Current documented exploits can be found on the cve.mitre.org webpage.
That webpage is a great way to find known issues with an existing CVE number, but it can be a little difficult to do a generalized search with it. In this case, a website called www.cvedetails.com may be a better option for finding existing Windows 10 exploits. CveDetails.Com is nothing more than a front-end search tool for the CVE database.
delivered to your inbox.
By submitting this form you agree to receive marketing emails from CBT Nuggets and that you have read, understood and are able to consent to our privacy policy.